GitVersion.yml relocation + YAML conventions - #35
Merged
Merged
Conversation
Decluttering the repo root, per the user's own review of the version/ calculate action. configFilePath is already an explicit input to gitversion/execute, so consumers update their own path independently - covered separately when this reaches .actions. Lowercased on the move: GitVersion is the tool's own name, not a filename convention this repo needs to preserve. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
It was listed under Verbatim, but that's never been true: next-version is a deliberate per-repo bootstrap value (.actions starts at 1.0.0, this repo at 0.0.1), not drift to reconcile. Moved to Edit in place, the category that already exists for exactly this shape - the base owns the whole file except one key, which each repo sets for itself. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Enforced, not just documented: yaml.format.singleQuote on the formatter already configured as default for [yaml], with formatOnSave already on. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
version/calculate's Report version step already does this (steps.gitversion.outputs.semVer isn't attacker-controlled, but the pattern is cheap enough to apply uniformly rather than re-judging it per value) - covered separately when the comment lands there. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
39 values across the issue forms, codecov.yml, settings.yml, and template-sync.yml's cron - hex colors, globs, a cron expression, and issue-title prefixes, none of which contain an apostrophe. Two double-quoted instances left untouched: they're prose inside comments (codecov.yml:121, settings.yml:3), not YAML string values. Confirmed the label colors specifically: read repository-settings/app's own labels.js (strips any leading # before calling the API either way) and its current docs (which recommend single quotes, `color: '#336699'`), and reproduced parsing '#9aff00' and "#9aff00" through the exact pinned js-yaml version - identical result. No double-quote requirement exists; the real, documented hazard is unquoted vs quoted (an unquoted #RRGGBB is read as a YAML comment). Verified: 599 assertions, 0 failed; every touched file parses and is CRLF. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
TaffarelJr
force-pushed
the
feat/gitversion-and-yaml-conventions
branch
from
September 21, 2026 01:55
7d1cc7f to
c1c2ea4
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Five separate commits, each a distinct concern - see the log rather than
this summary for the detail on any one of them:
gitversion.ymlunder.github/, lowercased and decluttered fromthe root -
configFilePathis already an explicit input togitversion/execute.docs/TemplateChain.md: it was listed under Verbatim,which was never true -
next-versionis a deliberate per-repo bootstrapvalue. Moved to Edit in place.
yaml.instructions.md, and enforced (not just documented) viayaml.format.singleQuoteon the formatter already default for[yaml].${{ }}value throughenv:rather thaninterpolating it into
run:- GitHub's own security hardening guide'snamed mitigation for script injection, applied uniformly rather than
judged value by value.
left alone because they're prose inside comments, not real YAML strings.
Checked the one value type worth real scrutiny (settings.yml's label
colors) against
repository-settings/app's own source and currentdocs, and reproduced the parse through the exact pinned
js-yamlversion - no double-quote requirement exists for them.
Verified: 599 assertions, 0 failed; every touched file parses and is CRLF.
🤖 Generated with Claude Code