fix(seed): branch protection honours reforge.requiredApprovers
reforge-seed hardcoded approvals_whitelist_username to security-lead, so seeded stack repos ignored the module option that the working repo already respected. The package now bakes REFORGE_REQUIRED_APPROVERS in from the option (space-separated, standalone default unchanged) and the seed script builds the protection payload from it. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
parent
109c5e2514
commit
a8b85154b8
3 changed files with 17 additions and 4 deletions
|
|
@ -37,6 +37,7 @@
|
|||
configDir,
|
||||
agentsDir ? null,
|
||||
refsDir ? null,
|
||||
requiredApprovers ? [ "security-lead" ],
|
||||
}:
|
||||
|
||||
let
|
||||
|
|
@ -88,6 +89,7 @@ stdenvNoCC.mkDerivation {
|
|||
--set-default REFORGE_CONFIG_DIR ${lib.escapeShellArg (toString configDir)} \
|
||||
--set-default REFORGE_SETTINGS_DIR "$SETTINGS" \
|
||||
--set-default REFORGE_AGENTS_DIR "$AGENTS" \
|
||||
--set-default REFORGE_REQUIRED_APPROVERS ${lib.escapeShellArg (lib.concatStringsSep " " requiredApprovers)} \
|
||||
${lib.optionalString (
|
||||
refsDir != null
|
||||
) "--set-default REFORGE_REFS_DIR ${lib.escapeShellArg (toString refsDir)}"}
|
||||
|
|
@ -96,7 +98,7 @@ stdenvNoCC.mkDerivation {
|
|||
'';
|
||||
|
||||
meta = with lib; {
|
||||
description = "reforge lifecycle CLI (seed/reset/compare/smoke/kickoff/role/orchestrator/fetch-targets)";
|
||||
description = "reforge lifecycle CLI (seed/reset/compare/smoke/kickoff/role/orchestrator/fetch-targets/harvest)";
|
||||
mainProgram = "reforge-seed";
|
||||
license = licenses.mit;
|
||||
};
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue