Skip to content

feat: accept both .yml and .yaml Security Insights filenames - #70

Merged
jmeridth merged 2 commits into
mainfrom
feat/accept-yaml-extension
Oct 8, 2026
Merged

jmeridth merged 2 commits into
mainfrom
feat/accept-yaml-extension

Conversation

@jmeridth

@jmeridth jmeridth commented Oct 7, 2026

Copy link
Copy Markdown
Member

Relates to ossf/security-insights#212

What/Why

The spec is moving to accept security-insights.yaml as well as security-insights.yml. This adds SecurityInsightsFilenames(), which returns both names with .yml first, so consumers such as the OSPS Baseline scanner can find either one. SecurityInsightsFilename is deprecated but unchanged.

Proof it works

New TestSecurityInsightsFilenames covers the names and that callers get a fresh slice. go test, golangci-lint, and make covcheck (76.5%) pass.

Risk

Low. Additive only.

AI role

Drafted by Claude Opus 5.5. The maintainer chose the function shape and the deprecation, and reviewed the diff.

Review focus

The .yml-first order. The scanner will rely on it to fall back to .yml when a repository has both files.

What/Why
The spec now accepts security-insights.yaml as well as .yml.
SecurityInsightsFilenames() returns both, .yml first, so consumers such
as the OSPS Baseline scanner can find either. SecurityInsightsFilename
is deprecated.

Proof it works
New TestSecurityInsightsFilenames. go test, golangci-lint, and make
covcheck (76.5%) pass.

Risk
Low. Additive. The deprecated constant is unchanged.

AI role
Drafted by Claude Opus 5.5 and reviewed by the maintainer, who chose
the function shape and the deprecation.

Review focus
The .yml-first order, which consumers rely on to fall back to .yml when
both files exist.

Signed-off-by: jmeridth <jmeridth@gmail.com>
@jmeridth jmeridth self-assigned this Oct 7, 2026
@jmeridth
jmeridth marked this pull request as ready for review October 8, 2026 03:07
@jmeridth
jmeridth requested a review from a team as a code owner October 8, 2026 03:07
What/Why
Names the release v2.2.1, matching spec v2.2.0, and records the
in-scope and out-of-scope loading fix from #71.

Proof it works
Docs only.

Risk
Low. The bug fix entry describes #71, which must merge before the tag.

AI role
Drafted by Claude Opus 5.5. The maintainer chose the version.

Review focus
The version number.

Signed-off-by: jmeridth <jmeridth@gmail.com>
@jmeridth
jmeridth requested a review from eddie-knight October 8, 2026 14:37
@jmeridth
jmeridth merged commit 73adf4b into main Oct 8, 2026
3 checks passed
eddie-knight added a commit to eddie-knight/si-tooling that referenced this pull request Oct 8, 2026
Resolves conflicts with ossf#70 (.yml and .yaml filenames) and ossf#71 (scope
string lists). Keeps ErrParentUnavailable and the timed HTTP client from
this branch, takes SecurityInsightsFilenames from main, and folds the
.yaml name into Discover so the new spelling is found too.

Signed-off-by: Eddie Knight <knight@linux.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants