Repository navigation
fix: load in-scope and out-of-scope as string lists and test the spec examples - #71
Merged
Merged
Conversation
Fixes #68 What/Why The schema declares in-scope and out-of-scope as string lists, but the generated types made them *URL. The strict loader then rejected every file that set either field. Both are now []string. Proof it works TestLoadV220Fields now loads a fixture with both fields. Without the type change it fails with "cannot unmarshal []interface {} into ... si.URL", the error in the issue. go test, golangci-lint, and make covcheck (76.2%) pass. Risk Low. The field type change is an API break on paper, but no file that set these fields could load before, and no known consumer reads them. AI role Drafted by Claude Opus 5.5 and reviewed by the maintainer. Review focus generated_types.go is hand-edited for these two fields only. A full regeneration from the current spec also changes Project and Repository from pointers to values, which needs its own change. Signed-off-by: jmeridth <jmeridth@gmail.com>
jmeridth
added a commit
that referenced
this pull request
Oct 8, 2026
What/Why Names the release v2.2.1, matching spec v2.2.0, and records the in-scope and out-of-scope loading fix from #71. Proof it works Docs only. Risk Low. The bug fix entry describes #71, which must merge before the tag. AI role Drafted by Claude Opus 5.5. The maintainer chose the version. Review focus The version number. Signed-off-by: jmeridth <jmeridth@gmail.com>
jmeridth
marked this pull request as ready for review
October 8, 2026 07:31
Closes #72 What/Why The tests only loaded "minimal" fixtures, so the spec's own example-full.yml failed to load (#68) without any test noticing. The four v2.2.0 spec examples now live unmodified in test_data/spec-v2.2.0, and TestLoadSpecExamples loads each one. The in-scope fields added to minimal-v2.2.0.yml earlier in this branch are reverted, since that fixture is meant to stay minimal. Proof it works TestLoadSpecExamples passes. With the old *URL types, the full example fails with the #68 unmarshal error. The reuse example's parent is served by httptest, so no test touches the network. make check-spec-examples confirms the fixtures match the v2.2.0 tag. go test, golangci-lint, and make covcheck (76.2%) pass. Risk Low. Tests and a Makefile target only. AI role Drafted by Claude Opus 5.5 and reviewed by the maintainer. Review focus Whether check-spec-examples should also run in CI. Signed-off-by: jmeridth <jmeridth@gmail.com>
eddie-knight
approved these changes
Oct 8, 2026
eddie-knight
left a comment
Contributor
There was a problem hiding this comment.
These are not required values, but I just noticed that our test data only contains files marked "minimal."
eddie-knight
added a commit
to eddie-knight/si-tooling
that referenced
this pull request
Oct 8, 2026
Resolves conflicts with ossf#70 (.yml and .yaml filenames) and ossf#71 (scope string lists). Keeps ErrParentUnavailable and the timed HTTP client from this branch, takes SecurityInsightsFilenames from main, and folds the .yaml name into Discover so the new spelling is found too. Signed-off-by: Eddie Knight <knight@linux.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #68
Closes #72
What/Why
The schema declares
in-scopeandout-of-scopeas string lists, but the generated types made them*URL, so the strict loader rejected any file that set either field. Both are now[]string.The tests only used "minimal" fixtures, which is how the spec's own
example-full.ymlstopped loading without anyone noticing. The four Security Insights v2.2.0 examples now live unmodified inv2/si/test_data/spec-v2.2.0/, andTestLoadSpecExamplesloads each one.Proof it works
TestLoadSpecExamplespasses. With the old*URLtypes, the full example fails with the in-scope and out-of-scope generate as *URL, so any file that uses them fails to load #68 error,cannot unmarshal []interface {} into ... si.URL.httptest, so the tests stay offline.make check-spec-examplesconfirms the fixtures match the spec'sv2.2.0tag byte for byte.go test,golangci-lint, andmake covcheck(76.2%) pass.Risk
Low. The field type change is an API break on paper, but no file using these fields could load before, and no known consumer (including the OSPS Baseline scanner) reads them.
AI role
Drafted by Claude Opus 5.5 and reviewed by the maintainer.
Review focus
generated_types.gois hand-edited for these two fields only. Regenerating from the current spec also turnsProjectandRepositoryfrom pointers into values, which would break consumers and needs its own change. The schema fix that keeps future generation correct is fix(schema): generate in-scope and out-of-scope as string lists security-insights#213.check-spec-examplesshould also run in CI. It hits the network, so it's opt-in for now.