fix(seed): branch protection honours reforge.requiredApprovers

reforge-seed hardcoded approvals_whitelist_username to security-lead,
so seeded stack repos ignored the module option that the working repo
already respected. The package now bakes REFORGE_REQUIRED_APPROVERS in
from the option (space-separated, standalone default unchanged) and the
seed script builds the protection payload from it.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
Padreug 2026-10-09 18:45:44 +02:00
commit a8b85154b8
3 changed files with 17 additions and 4 deletions

View file

@ -73,12 +73,21 @@ ensure_repo() { # name description
fi
}
# Approver whitelist: the module bakes reforge.requiredApprovers in as
# REFORGE_REQUIRED_APPROVERS (space-separated); the standalone default
# matches the module's default. Field name is singular (Forgejo API quirk).
APPROVERS=${REFORGE_REQUIRED_APPROVERS:-security-lead}
PROTECTION_JSON=$(jq -cn --arg a "$APPROVERS" \
'{branch_name:"main",rule_name:"main",enable_push:false,required_approvals:1,
enable_approvals_whitelist:true,
approvals_whitelist_username:($a | split(" ") | map(select(length > 0))),
block_on_rejected_reviews:true,dismiss_stale_approvals:true}')
protect_main() { # name (same rule the module puts on the working repo)
if [ "$(api GET "/repos/$ORG/$1/branch_protections/main")" = 404 ]; then
must "$(api POST "/repos/$ORG/$1/branch_protections" \
'{"branch_name":"main","rule_name":"main","enable_push":false,"required_approvals":1,"enable_approvals_whitelist":true,"approvals_whitelist_username":["security-lead"],"block_on_rejected_reviews":true,"dismiss_stale_approvals":true}')" \
must "$(api POST "/repos/$ORG/$1/branch_protections" "$PROTECTION_JSON")" \
"protect $ORG/$1 main"
echo " protected main"
echo " protected main (approvers: $APPROVERS)"
fi
}