Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -170,7 +170,7 @@ Required checks are enforced by branch protection. Do not duplicate their checkl

### Release conventions

Use Conventional Commits so the release automation can determine the next version: `fix:` produces a patch release, `feat:` produces a minor release, and `!` or `BREAKING CHANGE:` produces a major release. Add `Release-As: x.y.z` only when a deliberate version override is needed. The release workflow maintains the changelog and GitHub release after changes land on `main`; npm publication is opt-in through `.github/template.yml`.
Use Conventional Commits so the release automation can determine the next version: `fix:` produces a patch release, `feat:` produces a minor release, and `!` or `BREAKING CHANGE:` produces a major release. Add `Release-As: x.y.z` only when a deliberate version override is needed. The release workflow maintains the changelog and GitHub release after changes land on `main`; npm publication is opt-in through `.github/code-foundry.yml`.

Security checks can be skipped when repository visibility or the GitHub plan does not support a feature. A skipped optional check must not be configured as a required status check.

Expand Down
22 changes: 12 additions & 10 deletions .github/actions/setup/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -205,8 +205,10 @@ runs:

javascript_package_manager=none
configured_package_manager=""
if [ -f .github/template.yml ]; then
configured_package_manager="$(awk -F': ' '/^package_manager:/ {print $2; exit}' .github/template.yml)"
config_file=.github/code-foundry.yml
[ -f "$config_file" ] || config_file=.github/template.yml
if [ -f "$config_file" ]; then
configured_package_manager="$(awk -F': ' '/^package_manager:/ {print $2; exit}' "$config_file")"
fi
case "$configured_package_manager" in
bun|pnpm|yarn|npm) javascript_package_manager="$configured_package_manager" ;;
Expand Down Expand Up @@ -387,7 +389,7 @@ runs:
if [ "$javascript" = true ] && task_language_needed javascript; then
add_configured_tool node
if { [ -f bun.lock ] || [ -f bun.lockb ] ||
awk -F': ' '/^package_manager:/ {print $2; exit}' .github/template.yml 2>/dev/null | grep -qx bun; }; then
config_file=.github/code-foundry.yml; [ -f "$config_file" ] || config_file=.github/template.yml; awk -F': ' '/^package_manager:/ {print $2; exit}' "$config_file" 2>/dev/null | grep -qx bun; }; then
add_configured_tool bun
fi
fi
Expand All @@ -401,7 +403,7 @@ runs:
javascript)
configured_tool node && mise_tools+=(node)
if { [ -f bun.lock ] || [ -f bun.lockb ] ||
awk -F': ' '/^package_manager:/ {print $2; exit}' .github/template.yml 2>/dev/null | grep -qx bun; } && configured_tool bun; then
config_file=.github/code-foundry.yml; [ -f "$config_file" ] || config_file=.github/template.yml; awk -F': ' '/^package_manager:/ {print $2; exit}' "$config_file" 2>/dev/null | grep -qx bun; } && configured_tool bun; then
mise_tools+=(bun)
fi
;;
Expand Down Expand Up @@ -449,12 +451,12 @@ runs:
(inputs.cache-installed == 'true' ||
steps.profile.outputs.javascript_package_manager == 'pnpm' ||
steps.profile.outputs.javascript_package_manager == 'yarn') &&
hashFiles('**/package.json', '**/bun.lock', '**/bun.lockb', '**/pnpm-lock.yaml', '**/yarn.lock', '**/package-lock.json', '**/.npmrc', '**/.yarnrc*', '**/.pnpmfile.cjs', '.github/template.yml', '.mise.toml', 'mise.lock') != ''
hashFiles('**/package.json', '**/bun.lock', '**/bun.lockb', '**/pnpm-lock.yaml', '**/yarn.lock', '**/package-lock.json', '**/.npmrc', '**/.yarnrc*', '**/.pnpmfile.cjs', '.github/code-foundry.yml', '.github/template.yml', '.mise.toml', 'mise.lock') != ''
uses: actions/cache/restore@v5
with:
path: |
**/node_modules
key: ${{ runner.os }}-javascript-installed-v3-${{ hashFiles('**/package.json', '**/bun.lock', '**/bun.lockb', '**/pnpm-lock.yaml', '**/yarn.lock', '**/package-lock.json', '**/.npmrc', '**/.yarnrc*', '**/.pnpmfile.cjs', '.github/template.yml', '.mise.toml', 'mise.lock') }}
key: ${{ runner.os }}-javascript-installed-v3-${{ hashFiles('**/package.json', '**/bun.lock', '**/bun.lockb', '**/pnpm-lock.yaml', '**/yarn.lock', '**/package-lock.json', '**/.npmrc', '**/.yarnrc*', '**/.pnpmfile.cjs', '.github/code-foundry.yml', '.github/template.yml', '.mise.toml', 'mise.lock') }}
- name: Restore Bun dependencies
id: javascript-bun-cache-restore
if: >-
Expand All @@ -463,12 +465,12 @@ runs:
inputs.cache-installed != 'false' &&
steps.profile.outputs.javascript_dependencies == 'true' &&
steps.profile.outputs.javascript_package_manager == 'bun' &&
hashFiles('**/package.json', '**/bun.lock', '**/bun.lockb', '**/.npmrc', '.github/template.yml', '.mise.toml', 'mise.lock') != ''
hashFiles('**/package.json', '**/bun.lock', '**/bun.lockb', '**/.npmrc', '.github/code-foundry.yml', '.github/template.yml', '.mise.toml', 'mise.lock') != ''
uses: actions/cache/restore@v5
with:
path: |
**/node_modules
key: ${{ runner.os }}-javascript-installed-v4-bun-${{ hashFiles('**/package.json', '**/bun.lock', '**/bun.lockb', '**/.npmrc', '.github/template.yml', '.mise.toml', 'mise.lock') }}
key: ${{ runner.os }}-javascript-installed-v4-bun-${{ hashFiles('**/package.json', '**/bun.lock', '**/bun.lockb', '**/.npmrc', '.github/code-foundry.yml', '.github/template.yml', '.mise.toml', 'mise.lock') }}
- name: Detect Bun dependencies
id: javascript-bun-dependencies
if: >-
Expand Down Expand Up @@ -735,7 +737,7 @@ runs:
with:
path: |
**/node_modules
key: ${{ runner.os }}-javascript-installed-v4-bun-${{ hashFiles('**/package.json', '**/bun.lock', '**/bun.lockb', '**/.npmrc', '.github/template.yml', '.mise.toml', 'mise.lock') }}
key: ${{ runner.os }}-javascript-installed-v4-bun-${{ hashFiles('**/package.json', '**/bun.lock', '**/bun.lockb', '**/.npmrc', '.github/code-foundry.yml', '.github/template.yml', '.mise.toml', 'mise.lock') }}
- name: Save installed JavaScript dependencies
if: >-
inputs.cache-save == 'true' &&
Expand All @@ -751,7 +753,7 @@ runs:
with:
path: |
**/node_modules
key: ${{ runner.os }}-javascript-installed-v3-${{ hashFiles('**/package.json', '**/bun.lock', '**/bun.lockb', '**/pnpm-lock.yaml', '**/yarn.lock', '**/package-lock.json', '**/.npmrc', '**/.yarnrc*', '**/.pnpmfile.cjs', '.github/template.yml', '.mise.toml', 'mise.lock') }}
key: ${{ runner.os }}-javascript-installed-v3-${{ hashFiles('**/package.json', '**/bun.lock', '**/bun.lockb', '**/pnpm-lock.yaml', '**/yarn.lock', '**/package-lock.json', '**/.npmrc', '**/.yarnrc*', '**/.pnpmfile.cjs', '.github/code-foundry.yml', '.github/template.yml', '.mise.toml', 'mise.lock') }}
- name: Save JavaScript packages
if: >-
inputs.cache-save == 'true' &&
Expand Down
25 changes: 25 additions & 0 deletions .github/code-foundry.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@
# Canonical Code Foundry repository configuration.
version: 1
template: code-foundry@latest
profile: auto
languages: typescript
features: all
package_manager: bun
runtime_repository: 0xPlayerOne/code-foundry
runtime_ref: v0.20.2
release_type: node
npm_publish: true
license: agpl-3.0-or-later
runner: ubuntu-latest
unit_runner: ubuntu-slim
cache_packages: auto
cache_build: auto
coverage_minimum: 80
turbo_remote: auto
ci_runner: ubuntu-latest
test_runner: ubuntu-latest
security_runner: ubuntu-slim
codeql_runner: ubuntu-latest
pr_runner: ubuntu-slim
release_runner: ubuntu-slim
prune_standard: false
41 changes: 41 additions & 0 deletions .github/code-foundry.yml.example
Original file line number Diff line number Diff line change
@@ -0,0 +1,41 @@
# Copy this file to .github/code-foundry.yml, edit the values you need, and run:
# npx code-foundry init --config .github/code-foundry.yml
# Omitted keys use automatic detection and the standard defaults. See
# docs/CONFIGURATION.md for the complete visual reference.

version: 1

# Repository shape and supported languages.
profile: auto # auto, application, monorepo, minimal
languages: auto # auto or typescript,rust,python,solidity
package_manager: auto # auto, bun, pnpm, yarn, npm

# Standard callers to install. Use `all` or a comma-separated selection.
features: all # ci, codeql, security, test, draft-pr, release-pr, release, dependabot

# Runtime source. Leave blank to infer it from the template source.
runtime_repository: # OWNER/REPO, or leave blank to infer
runtime_ref: # tag or branch, or leave blank for default

# Release and licensing behavior.
release_type: auto # auto, node, python, rust, simple, none
npm_publish: false
license: preserve # agpl-3.0-or-later, mit, preserve, none
# license_file: ./legal/LICENSE.txt

# Runner policy. Each workflow caller receives its selected runner.
runner: ubuntu-latest
unit_runner: ubuntu-slim
ci_runner: ubuntu-latest
test_runner: ubuntu-latest
security_runner: ubuntu-slim
codeql_runner: ubuntu-latest
pr_runner: ubuntu-slim
release_runner: ubuntu-slim
prune_standard: false # remove disabled standard workflows during sync

# Cache and quality policy.
cache_packages: auto # auto, true, false
cache_build: auto # auto, true, false
coverage_minimum: 80
turbo_remote: auto # auto, true, false
2 changes: 1 addition & 1 deletion .github/scripts/changed-files.sh
Original file line number Diff line number Diff line change
Expand Up @@ -72,7 +72,7 @@ repo_foundry_pr_dependencies_unchanged() {
while IFS= read -r file; do
case "$file" in
.github/workflows/security.yml|.github/scripts/security.sh|.github/scripts/changed-files.sh|\
.github/actions/setup/action.yml|.github/template.yml|.mise.toml|mise.lock|\
.github/actions/setup/action.yml|.github/code-foundry.yml|.github/template.yml|.mise.toml|mise.lock|\
.github/security-audit-allowlist.txt)
return 1
;;
Expand Down
8 changes: 6 additions & 2 deletions .github/scripts/ci.sh
Original file line number Diff line number Diff line change
Expand Up @@ -93,8 +93,12 @@ package_manager() {
local configured=""
if [ -x .github/scripts/profile.sh ]; then
configured="$(bash .github/scripts/profile.sh get package_manager 2>/dev/null || true)"
elif [ -f .github/template.yml ]; then
configured="$(awk -F': ' '/^package_manager:/ {print $2; exit}' .github/template.yml)"
else
config_file=.github/code-foundry.yml
[ -f "$config_file" ] || config_file=.github/template.yml
if [ -f "$config_file" ]; then
configured="$(awk -F': ' '/^package_manager:/ {print $2; exit}' "$config_file")"
fi
fi
case "$configured" in
bun|pnpm|yarn|npm) echo "$configured"; return ;;
Expand Down
8 changes: 6 additions & 2 deletions .github/scripts/codeql-languages.sh
Original file line number Diff line number Diff line change
Expand Up @@ -25,8 +25,12 @@ if find .github/workflows -type f \( -name '*.yml' -o -name '*.yaml' \) -print -
configured=""
if [ -x .github/scripts/profile.sh ]; then
configured="$(bash .github/scripts/profile.sh get languages 2>/dev/null || true)"
elif [ -f .github/template.yml ]; then
configured="$(awk -F': ' '/^languages:/ {print $2; exit}' .github/template.yml)"
else
config_file=.github/code-foundry.yml
[ -f "$config_file" ] || config_file=.github/template.yml
if [ -f "$config_file" ]; then
configured="$(awk -F': ' '/^languages:/ {print $2; exit}' "$config_file")"
fi
fi

if [ "$configured" = auto ] || [ "$configured" = all ] || [ -z "$configured" ]; then
Expand Down
6 changes: 4 additions & 2 deletions .github/scripts/doctor.sh
Original file line number Diff line number Diff line change
Expand Up @@ -4,8 +4,10 @@ set -euo pipefail
errors=0

configured_features="all"
if [ -f .github/template.yml ]; then
configured_features="$(awk -F': ' '/^features:/ {print $2; exit}' .github/template.yml)"
config_file=.github/code-foundry.yml
[ -f "$config_file" ] || config_file=.github/template.yml
if [ -f "$config_file" ]; then
configured_features="$(awk -F': ' '/^features:/ {print $2; exit}' "$config_file")"
[ -n "$configured_features" ] || configured_features="all"
fi

Expand Down
Loading