-
Notifications
You must be signed in to change notification settings - Fork 28
refactor: modernize make/generate.mk with versioned tool binaries and modernize project docs
#519
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
4b29578
69b1738
84267dd
36bd266
b2e67fc
d429f03
a80c1ef
96b1f15
b1ebcea
b97b57c
1521e6c
521fd43
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,25 @@ | ||
| --- | ||
| name: commit-with-message | ||
| description: Create a commit with a message based on the staged changes | ||
|
|
||
| --- | ||
|
|
||
| 1. Pre-check | ||
|
|
||
| Abort if there is no staged changes | ||
| Abort if there are openspec changes that have not been archived (ie, there are sibling folders to `openspec/changes/archive`) | ||
|
|
||
| 2. Prepare a commit message for the staged changes | ||
|
|
||
| - Suggest a commit message based on the **staged only** changes | ||
| - Do not mention the changes in the `/openspec` folder | ||
| - Surround folder names, file names, variable names, function and method names by backticks (`) | ||
| - Use the Conventional Commits from https://www.conventionalcommits.org/en/v1.0.0/ | ||
| - Include the "Assisted-by:" trail with the name of the current model | ||
|
|
||
| Show the suggested message and prompt the user to confirm that we shall proceed with committing the staged changes | ||
| Abort if the user is not happy with the message | ||
|
|
||
| 3. Commit | ||
|
|
||
| run the `git commit -s` command with the message prepared above | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔒 Security & Privacy | 🟠 Major | ⚡ Quick win 🧩 Analysis chain🏁 Script executed: #!/bin/sh
set -u
git commit -h 2>&1 | grep -E -- '(-s, --signoff|-S, --gpg-sign)' || trueRepository: codeready-toolchain/api Length of output: 161 🏁 Script executed: #!/bin/sh
set -u
printf '%s\n' '--- target file ---'
cat -n .claude/commands/commit-with-message.md | sed -n '1,80p'
printf '%s\n' '--- signing-related references ---'
rg -n -i --hidden --glob '!/.git/**' 'signed|sign[- ]off|gpg|commit -s|commit -S|cryptograph' .claude README* .github 2>/dev/null || true
printf '%s\n' '--- local Git option behavior ---'
git commit --help 2>&1 | grep -E -- '(-s, --signoff|-S, --gpg-sign)' || true
git commit -h 2>&1 | sed -n '/signoff\|gpg-sign/p'Repository: codeready-toolchain/api Length of output: 1568 Use cryptographic signing when required.
🤖 Prompt for AI Agents |
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,2 +1,19 @@ | ||
| ignored-vulnerabilities: [] | ||
|
|
||
| ignored-vulnerabilities: | ||
| # Incorrect parsing of IPv6 host literals in net/url | ||
| # Found in: net/url@go1.24.13 | ||
| # Fixed in: net/url@go1.25.8 | ||
| - id: GO-2026-4601 | ||
| silence-until: 2026-09-03 | ||
| info: https://pkg.go.dev/vuln/GO-2026-4601 | ||
| # Inefficient candidate hostname parsing in crypto/x509 | ||
| # Found in: crypto/x509@go1.24.13 | ||
| # Fixed in: crypto/x509@go1.25.11 | ||
| - id: GO-2026-5037 | ||
| silence-until: 2026-09-03 | ||
| info: https://pkg.go.dev/vuln/GO-2026-5037 | ||
| # FileInfo can escape from a Root in os | ||
| # Found in: os@go1.24.13 | ||
| # Fixed in: os@go1.25.8 | ||
| - id: GO-2026-4602 | ||
| info: https://pkg.go.dev/vuln/GO-2026-4602 | ||
| silence-until: 2026-09-03 |
This file was deleted.
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,31 @@ | ||
| # ToolChain API | ||
|
|
||
| [](https://goreportcard.com/report/github.com/codeready-toolchain/api) | ||
| [](https://godoc.org/github.com/codeready-toolchain/api) | ||
|
|
||
| For the API reference docs go [here](api/v1alpha1/docs/apiref.adoc) | ||
|
|
||
| ## Prerequisites | ||
|
|
||
| * Go version 1.24.x (1.24.4 or higher) - download for your development environment [here](https://golang.org/dl/). | ||
|
|
||
| CodeReady ToolChain API is built using [Go modules](https://github.com/golang/go/wiki/Modules). | ||
|
|
||
| ## Modifying the API Types | ||
|
|
||
| The API types are defined in the `api/v1alpha1/*_types.go` files. After modifying these files, you must regenerate the derived files (deepcopy, OpenAPI, CRD manifests, and API reference docs) by running: | ||
|
|
||
| ```sh | ||
| make generate | ||
| ``` | ||
|
|
||
| This command runs the following steps: | ||
|
|
||
| 1. **Generate deepcopy and CRDs** — uses [controller-gen](https://github.com/kubernetes-sigs/controller-tools) to regenerate `zz_generated.deepcopy.go` and the CRD manifests in `config/crd/bases/`. | ||
| 2. **Generate OpenAPI** — uses [openapi-gen](https://github.com/kubernetes/kube-openapi) to regenerate `zz_generated.openapi.go`. | ||
| 3. **Generate API reference docs** — uses [crd-ref-docs](https://github.com/elastic/crd-ref-docs) to regenerate `api/v1alpha1/docs/apiref.adoc`. | ||
| 4. **Dispatch CRDs** — copies the generated CRD `.yaml` files to the `host-operator` and `member-operator` repositories. | ||
|
coderabbitai[bot] marked this conversation as resolved.
|
||
|
|
||
| > **Note:** The CRD dispatch step assumes the `host-operator` and `member-operator` repositories have been checked out alongside this repository and that *they are in a clean state*, meaning that they have no pending changes besides previous versions of the CRD files. | ||
|
|
||
| > **Note:** After running `make generate`, you are expected to create PRs in this repository as well as in the `host-operator` and `member-operator` repositories where the CRD changes were propagated. Please do not mix other code changes with CRD changes — it is always preferred to promote CRD changes separately for easier PR review. | ||
This file was deleted.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🔒 Security & Privacy | 🟠 Major | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
Repository: codeready-toolchain/api
Length of output: 2861
🏁 Script executed (no clone):
Length of output: 513
🏁 Script executed (no clone):
Length of output: 646
🏁 Script executed (no clone):
Length of output: 198
Pass the commit message as data, not shell text.
When the message is interpolated into a shell command, backticks and other shell metacharacters can execute commands or alter arguments. Write the confirmed message to a temporary file and use
git commit -s --file "$message_file"without interpolation. Remove the temporary file after the commit attempt.🤖 Prompt for AI Agents
Source: Path instructions