Repository navigation
feat: accept both .yml and .yaml Security Insights filenames - #70
Merged
Merged
Conversation
What/Why The spec now accepts security-insights.yaml as well as .yml. SecurityInsightsFilenames() returns both, .yml first, so consumers such as the OSPS Baseline scanner can find either. SecurityInsightsFilename is deprecated. Proof it works New TestSecurityInsightsFilenames. go test, golangci-lint, and make covcheck (76.5%) pass. Risk Low. Additive. The deprecated constant is unchanged. AI role Drafted by Claude Opus 5.5 and reviewed by the maintainer, who chose the function shape and the deprecation. Review focus The .yml-first order, which consumers rely on to fall back to .yml when both files exist. Signed-off-by: jmeridth <jmeridth@gmail.com>
What/Why Names the release v2.2.1, matching spec v2.2.0, and records the in-scope and out-of-scope loading fix from #71. Proof it works Docs only. Risk Low. The bug fix entry describes #71, which must merge before the tag. AI role Drafted by Claude Opus 5.5. The maintainer chose the version. Review focus The version number. Signed-off-by: jmeridth <jmeridth@gmail.com>
eddie-knight
approved these changes
Oct 8, 2026
eddie-knight
added a commit
to eddie-knight/si-tooling
that referenced
this pull request
Oct 8, 2026
Resolves conflicts with ossf#70 (.yml and .yaml filenames) and ossf#71 (scope string lists). Keeps ErrParentUnavailable and the timed HTTP client from this branch, takes SecurityInsightsFilenames from main, and folds the .yaml name into Discover so the new spelling is found too. Signed-off-by: Eddie Knight <knight@linux.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Relates to ossf/security-insights#212
What/Why
The spec is moving to accept
security-insights.yamlas well assecurity-insights.yml. This addsSecurityInsightsFilenames(), which returns both names with.ymlfirst, so consumers such as the OSPS Baseline scanner can find either one.SecurityInsightsFilenameis deprecated but unchanged.Proof it works
New
TestSecurityInsightsFilenamescovers the names and that callers get a fresh slice.go test,golangci-lint, andmake covcheck(76.5%) pass.Risk
Low. Additive only.
AI role
Drafted by Claude Opus 5.5. The maintainer chose the function shape and the deprecation, and reviewed the diff.
Review focus
The
.yml-first order. The scanner will rely on it to fall back to.ymlwhen a repository has both files.