feat(spinel-coop/rv): GitHub artifact attestations config#49919
Conversation
|
Caution Review failedThe pull request is closed. ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (1)
📝 WalkthroughWalkthroughAdds new version-specific package entries and manifest fields: a version_override for semver("<= 0.5.2") with asset naming, replacements, tar.xz format, github_release sha256 checksum, supported_envs (linux, darwin), and a github_artifact_attestations signer_workflow; also adds a new package entry for v0.5.2. Changes
Estimated code review effort🎯 2 (Simple) | ⏱️ ~10 minutes Suggested labels
Poem
🚥 Pre-merge checks | ✅ 3✅ Passed checks (3 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
🧹 Nitpick comments (1)
pkgs/spinel-coop/rv/registry.yaml (1)
38-40: Drop the quotes around{{.Asset}}.sha256.This value does not need YAML quoting, and the repo style for
registry.yamlasks to omit unnecessary quotes.Suggested cleanup
checksum: type: github_release - asset: "{{.Asset}}.sha256" + asset: {{.Asset}}.sha256 algorithm: sha256As per coding guidelines, "Remove unnecessary quotes from string values in registry.yaml".
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed. In `@pkgs/spinel-coop/rv/registry.yaml` around lines 38 - 40, The checksum.asset value currently uses unnecessary YAML quotes: change the asset field in the checksum block (where type: github_release and asset: "{{.Asset}}.sha256") to remove the quotes so it reads asset: {{.Asset}}.sha256, preserving the template exactly but following the registry.yaml style guideline.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Nitpick comments:
In `@pkgs/spinel-coop/rv/registry.yaml`:
- Around line 38-40: The checksum.asset value currently uses unnecessary YAML
quotes: change the asset field in the checksum block (where type: github_release
and asset: "{{.Asset}}.sha256") to remove the quotes so it reads asset:
{{.Asset}}.sha256, preserving the template exactly but following the
registry.yaml style guideline.
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro
Run ID: 5465a201-fb63-4d3e-aa0d-e219d4968d65
📒 Files selected for processing (2)
pkgs/spinel-coop/rv/registry.yamlregistry.yaml
|
Thank you always! |
This MR contains the following updates: | Package | Update | Change | |---|---|---| | [aquaproj/aqua-registry](https://github.com/aquaproj/aqua-registry) | minor | `v4.476.0` → `v4.481.0` | MR created with the help of [el-capitano/tools/renovate-bot](https://gitlab.com/el-capitano/tools/renovate-bot). **Proposed changes to behavior should be submitted there as MRs.** --- ### Release Notes <details> <summary>aquaproj/aqua-registry (aquaproj/aqua-registry)</summary> ### [`v4.481.0`](https://github.com/aquaproj/aqua-registry/releases/tag/v4.481.0) [Compare Source](aquaproj/aqua-registry@v4.480.0...v4.481.0) [Issues](https://github.com/aquaproj/aqua-registry/issues?q=is%3Aissue+milestone%3Av4.481.0) | [Merge Requests](https://github.com/aquaproj/aqua-registry/pulls?q=is%3Apr+milestone%3Av4.481.0) | <aquaproj/aqua-registry@v4.480.0...v4.481.0> #### 🎉 New Packages [#​50135](aquaproj/aqua-registry#50135) [raaymax/lazytail](https://github.com/raaymax/lazytail): Log viewer for app development [@​hituzi-no-sippo](https://github.com/hituzi-no-sippo) [#​50093](aquaproj/aqua-registry#50093) [stackrox/stackrox/roxctl](https://github.com/stackrox/stackrox) - CLI for StackRox Kubernetes Security Platform [@​sebdanielsson](https://github.com/sebdanielsson) #### Improvement [#​50136](aquaproj/aqua-registry#50136) hellux/jotdown: Add search words `djot` [@​hituzi-no-sippo](https://github.com/hituzi-no-sippo) [#​50164](aquaproj/aqua-registry#50164) Use preferred signer\_workflow spelling [@​scop](https://github.com/scop) #### Fixes [#​50085](aquaproj/aqua-registry#50085) mvdan/sh: Starting v3.13.0, no longer includes a sha256sums.txt asset [@​adilsyed518](https://github.com/adilsyed518) #### Security Configure GitHub Immutable Release config by [@​scop](https://github.com/scop) [#​50115](aquaproj/aqua-registry#50115) twpayne/chezmoi [#​50114](aquaproj/aqua-registry#50114) suzuki-shunsuke/ghir [#​50113](aquaproj/aqua-registry#50113) suzuki-shunsuke/cmdx [#​50084](aquaproj/aqua-registry#50084) pnpm/pnpm [#​50081](aquaproj/aqua-registry#50081) jdx/usage [#​50077](aquaproj/aqua-registry#50077) jdx/mise [#​50076](aquaproj/aqua-registry#50076) jdx/hk [#​50075](aquaproj/aqua-registry#50075) j178/prek [#​50074](aquaproj/aqua-registry#50074) dprint/dprint ### [`v4.480.0`](https://github.com/aquaproj/aqua-registry/releases/tag/v4.480.0) [Compare Source](aquaproj/aqua-registry@v4.479.0...v4.480.0) [Issues](https://github.com/aquaproj/aqua-registry/issues?q=is%3Aissue+milestone%3Av4.480.0) | [Merge Requests](https://github.com/aquaproj/aqua-registry/pulls?q=is%3Apr+milestone%3Av4.480.0) | <aquaproj/aqua-registry@v4.479.0...v4.480.0> #### 🎉 New Packages [#​50019](aquaproj/aqua-registry#50019) [betterleaks/betterleaks](https://github.com/betterleaks/betterleaks): A Better Secrets Scanner built for configurability and speed [@​hituzi-no-sippo](https://github.com/hituzi-no-sippo) #### Fixes [#​50041](aquaproj/aqua-registry#50041) moonrepo/moon: Re-scaffold to support v2.0.0 or later [#​50020](aquaproj/aqua-registry#50020) swanysimon/markdownlint-rs: Rename to swanysimon/mdlint ### [`v4.479.0`](https://github.com/aquaproj/aqua-registry/releases/tag/v4.479.0) [Compare Source](aquaproj/aqua-registry@v4.478.0...v4.479.0) [Issues](https://github.com/aquaproj/aqua-registry/issues?q=is%3Aissue+milestone%3Av4.479.0) | [Merge Requests](https://github.com/aquaproj/aqua-registry/pulls?q=is%3Apr+milestone%3Av4.479.0) | <aquaproj/aqua-registry@v4.478.0...v4.479.0> #### 🎉 New Packages [#​49988](aquaproj/aqua-registry#49988) [princjef/gomarkdoc](https://github.com/princjef/gomarkdoc): Generate markdown documentation for Go (golang) code [#​49970](aquaproj/aqua-registry#49970) [majorcontext/moat](https://github.com/majorcontext/moat) - Run agents in containers with credential injection and full observability [@​joonas](https://github.com/joonas) [#​49969](aquaproj/aqua-registry#49969) [sudorandom/fauxrpc](https://github.com/sudorandom/fauxrpc) - Easily start a fake gRPC/gRPC-Web/Connect/REST server from protobufs [@​joonas](https://github.com/joonas) [#​49947](aquaproj/aqua-registry#49947) [apache/ant](https://github.com/apache/ant) - Apache Ant is a Java library and command-line tool whose mission is to drive processes described in build files as targets and extension points dependent upon each other [@​chadlwilson](https://github.com/chadlwilson) ### [`v4.478.0`](https://github.com/aquaproj/aqua-registry/releases/tag/v4.478.0) [Compare Source](aquaproj/aqua-registry@v4.477.0...v4.478.0) [Issues](https://github.com/aquaproj/aqua-registry/issues?q=is%3Aissue+milestone%3Av4.478.0) | [Merge Requests](https://github.com/aquaproj/aqua-registry/pulls?q=is%3Apr+milestone%3Av4.478.0) | <aquaproj/aqua-registry@v4.477.0...v4.478.0> #### 🎉 New Packages [#​49934](aquaproj/aqua-registry#49934) [suzuki-shunsuke/docfresh](https://github.com/suzuki-shunsuke/docfresh): Make document maintainable, reusable, and testable #### Security [#​49919](aquaproj/aqua-registry#49919) spinel-coop/rv: GitHub artifact attestations config [@​scop](https://github.com/scop) #### Fixes [#​49892](aquaproj/aqua-registry#49892) Re-scaffold cloudflare/cloudflared ### [`v4.477.0`](https://github.com/aquaproj/aqua-registry/releases/tag/v4.477.0) [Compare Source](aquaproj/aqua-registry@v4.476.0...v4.477.0) [Issues](https://github.com/aquaproj/aqua-registry/issues?q=is%3Aissue+milestone%3Av4.477.0) | [Merge Requests](https://github.com/aquaproj/aqua-registry/pulls?q=is%3Apr+milestone%3Av4.477.0) | <aquaproj/aqua-registry@v4.476.0...v4.477.0> #### 🎉 New Packages [#​49856](aquaproj/aqua-registry#49856) [k1LoW/mo](https://github.com/k1LoW/mo): mo is a Markdown viewer that opens .md files in a browser [#​49770](aquaproj/aqua-registry#49770) [#​49791](aquaproj/aqua-registry#49791) [rtk-ai/rtk](https://github.com/rtk-ai/rtk) - CLI proxy that reduces LLM token consumption by 60-90% on common dev commands. Single Rust binary, zero dependencies [@​NikitaCOEUR](https://github.com/NikitaCOEUR) [@​TyceHerrman](https://github.com/TyceHerrman) [#​49738](aquaproj/aqua-registry#49738) [yashikota/exiftool-go](https://github.com/yashikota/exiftool-go) - Pure Go ExifTool wrapper powered by WebAssembly [@​yashikota](https://github.com/yashikota) [#​49610](aquaproj/aqua-registry#49610) [datadog-labs/pup](https://github.com/datadog-labs/pup) - Give your AI agent a Pup — a CLI companion with 200+ commands across 33+ Datadog products [@​iwata](https://github.com/iwata) [#​49348](aquaproj/aqua-registry#49348) [huseyinbabal/taws](https://github.com/huseyinbabal/taws) - Terminal UI for AWS (taws) - A terminal-based AWS resource viewer and manager [@​TyceHerrman](https://github.com/TyceHerrman) #### Security [#​49707](aquaproj/aqua-registry#49707) owenlamont/ryl: GitHub artifact attestations config [@​scop](https://github.com/scop) [#​49340](aquaproj/aqua-registry#49340) astral-sh/ruff: GitHub artifact attestations config [@​scop](https://github.com/scop) [#​49344](aquaproj/aqua-registry#49344) rhysd/actionlint: GitHub artifact attestations config [@​scop](https://github.com/scop) [#​49345](aquaproj/aqua-registry#49345) caarlos0/fork-cleaner: GitHub artifact attestations config [@​scop](https://github.com/scop) [#​49418](aquaproj/aqua-registry#49418) block/goose: GitHub artifact attestations config [@​scop](https://github.com/scop) #### Fixes [#​49398](aquaproj/aqua-registry#49398) pre-commit/pre-commit: Exclude Windows from `supported_envs` [@​altendky](https://github.com/altendky) [#​49613](aquaproj/aqua-registry#49613) Rename kunobi-ninja/kunobi-releases to kunobi-ninja/kunobi [@​rawmind0](https://github.com/rawmind0) [#​49623](aquaproj/aqua-registry#49623) weaviate/weaviate: Remove hidden Unicode whitespace [@​jamietanna](https://github.com/jamietanna) [#​49652](aquaproj/aqua-registry#49652) technicalpickles/envsense: Add linux/arm64 support [@​technicalpickles](https://github.com/technicalpickles) [#​49753](aquaproj/aqua-registry#49753) mozilla/sccache): Support aarch64 [@​lahabana](https://github.com/lahabana) </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever MR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this MR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this MR, check this box --- This MR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My41NS4zIiwidXBkYXRlZEluVmVyIjoiNDMuNjAuNSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiUmVub3ZhdGUgQm90IiwiYXV0b21hdGlvbjpib3QtYXV0aG9yZWQiLCJkZXBlbmRlbmN5LXR5cGU6Om1pbm9yIl19-->
https://github.com/spinel-coop/rv/attestations
Registry is at 0.5.2 currently while attestations are available from 0.5.3 on, so no test coverage yet.
Check List
Require signed commits, so all commits must be signedcmdx sto scaffold codeSummary by CodeRabbit
New Features
Security