fix(seed): branch protection honours reforge.requiredApprovers

reforge-seed hardcoded approvals_whitelist_username to security-lead,
so seeded stack repos ignored the module option that the working repo
already respected. The package now bakes REFORGE_REQUIRED_APPROVERS in
from the option (space-separated, standalone default unchanged) and the
seed script builds the protection payload from it.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
Padreug 2026-10-09 18:45:44 +02:00
commit a8b85154b8
3 changed files with 17 additions and 4 deletions

View file

@ -49,6 +49,8 @@ let
inherit tokensDir stateDir;
configDir = toString cfg.configDir;
agentsDir = if cfg.agentsDir == null then null else toString cfg.agentsDir;
# Seeded stack repos get the same approver whitelist as the working repo.
requiredApprovers = cfg.requiredApprovers;
refsDir = if cfg.refsDir == null then null else toString cfg.refsDir;
};