feat: add shared repository ruleset governance - #1
Merged
Merged
Conversation
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
Signed-off-by: LibreSign automation <noreply@libresign.coop>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Introduces the first shared governance implementation for LibreCodeCoop and LibreSign.
This PR intentionally does not modify production rulesets yet. It establishes a testable core, caller-owned configuration, and dry-run paths first.
Architecture
Ruleset behavior
appinfo/info.xmlnextcloud-botbypass for Nextcloud apps--applyQuality baseline
The repository follows the same licensing and supply-chain expectations used by LibreSign:
REUSE.tomlfor formats where inline SPDX comments are inappropriateLICENSES/plus top-levelLICENSEactionlint.ymlvitest.ymltypescript.ymlreuse.ymlzizmor.ymlCurrent checks are green: actionlint, Vitest, TypeScript/build, REUSE, and zizmor.
The README is intentionally short and focused on project value and principles. Technical architecture, development instructions, and the Safe Settings evaluation live under
docs/.Safe Settings evaluation
Safe Settings was evaluated before implementing reconciliation here.
Its internal rulesets plugin already supports repository ruleset REST endpoints, but the current supported configuration flow treats
rulesetsas organization-level settings: repo/suborg schemas do not expose them andSettings.returnRepoSpecificConfigs()removesrulesetsbefore repository configuration is applied.That does not cover our GitHub Free use case, where public repository rulesets are available but organization-wide rulesets require a paid plan.
The implementation here therefore owns only repository-ruleset reconciliation. Safe Settings can still be used later for settings it supports well, and repository-level ruleset support is a candidate upstream contribution.
See
docs/safe-settings.mdfor details.Current-state validation
The implementation was compared with live LibreSign rulesets:
LibreSign/libresigncurrently has the expectednextcloud-botbypassLibreSign/documentationcurrently has only the base bypassLibreSign/.githubcurrently exposes only the base ruleset on GitHub, although its existing governance repository contains an additional CI ruleset definition; migration must distinguish desired config from currently applied stateMigration plan
sync-rulesets.sh.githubrepositories to caller config + shared implementationLibreSign/.githubonly after parity is proven