Skip to content

GitVersion.yml relocation + YAML conventions - #35

Merged
TaffarelJr merged 5 commits into
mainfrom
feat/gitversion-and-yaml-conventions
Sep 21, 2026
Merged

TaffarelJr merged 5 commits into
mainfrom
feat/gitversion-and-yaml-conventions

Conversation

@TaffarelJr

@TaffarelJr TaffarelJr commented Sep 21, 2026 •

Copy link
Copy Markdown
Owner

Five separate commits, each a distinct concern - see the log rather than
this summary for the detail on any one of them:

  1. Move gitversion.yml under .github/, lowercased and decluttered from
    the root - configFilePath is already an explicit input to
    gitversion/execute.
  2. Reclassify it in docs/TemplateChain.md: it was listed under Verbatim,
    which was never true - next-version is a deliberate per-repo bootstrap
    value. Moved to Edit in place.
  3. Standardize on single-quoted YAML strings - documented in
    yaml.instructions.md, and enforced (not just documented) via
    yaml.format.singleQuote on the formatter already default for [yaml].
  4. Document threading a computed ${{ }} value through env: rather than
    interpolating it into run: - GitHub's own security hardening guide's
    named mitigation for script injection, applied uniformly rather than
    judged value by value.
  5. Sweep every YAML file in this repo to match - 39 values converted, two
    left alone because they're prose inside comments, not real YAML strings.
    Checked the one value type worth real scrutiny (settings.yml's label
    colors) against repository-settings/app's own source and current
    docs, and reproduced the parse through the exact pinned js-yaml
    version - no double-quote requirement exists for them.

Verified: 599 assertions, 0 failed; every touched file parses and is CRLF.

🤖 Generated with Claude Code

TaffarelJr and others added 5 commits September 20, 2026 19:51
Decluttering the repo root, per the user's own review of the version/
calculate action. configFilePath is already an explicit input to
gitversion/execute, so consumers update their own path independently
- covered separately when this reaches .actions. Lowercased on the
move: GitVersion is the tool's own name, not a filename convention
this repo needs to preserve.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
It was listed under Verbatim, but that's never been true: next-version
is a deliberate per-repo bootstrap value (.actions starts at 1.0.0,
this repo at 0.0.1), not drift to reconcile. Moved to Edit in place,
the category that already exists for exactly this shape - the base
owns the whole file except one key, which each repo sets for itself.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Enforced, not just documented: yaml.format.singleQuote on the
formatter already configured as default for [yaml], with
formatOnSave already on.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
version/calculate's Report version step already does this
(steps.gitversion.outputs.semVer isn't attacker-controlled, but the
pattern is cheap enough to apply uniformly rather than re-judging it
per value) - covered separately when the comment lands there.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
39 values across the issue forms, codecov.yml, settings.yml, and
template-sync.yml's cron - hex colors, globs, a cron expression, and
issue-title prefixes, none of which contain an apostrophe. Two
double-quoted instances left untouched: they're prose inside comments
(codecov.yml:121, settings.yml:3), not YAML string values.

Confirmed the label colors specifically: read repository-settings/app's
own labels.js (strips any leading # before calling the API either way)
and its current docs (which recommend single quotes,
`color: '#336699'`), and reproduced parsing '#9aff00' and "#9aff00"
through the exact pinned js-yaml version - identical result. No
double-quote requirement exists; the real, documented hazard is
unquoted vs quoted (an unquoted #RRGGBB is read as a YAML comment).

Verified: 599 assertions, 0 failed; every touched file parses and is
CRLF.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@TaffarelJr
TaffarelJr force-pushed the feat/gitversion-and-yaml-conventions branch from 7d1cc7f to c1c2ea4 Compare September 21, 2026 01:55
@TaffarelJr
TaffarelJr merged commit f620b0e into main Sep 21, 2026
3 checks passed
@TaffarelJr
TaffarelJr deleted the feat/gitversion-and-yaml-conventions branch September 21, 2026 02:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant