|
1 | | -# SPDX-License-Identifier: AGPL-3.0-or-later |
| 1 | +# SPDX-License-Identifier: MPL-2.0 |
2 | 2 | # |
3 | 3 | # Repository settings for probot/settings GitHub App. |
4 | 4 | # https://github.com/probot/settings |
5 | 5 | # |
6 | 6 | # This file defines repository-level configuration that is automatically |
7 | 7 | # applied by the probot/settings app when changes are pushed to the default |
8 | 8 | # branch. Install the app at: https://github.com/apps/settings |
| 9 | +# |
| 10 | +# ─── THIS FILE MUST NEVER DECLARE REPOSITORY IDENTITY ───────────────────────── |
| 11 | +# |
| 12 | +# It carries NO `name`, `description`, `homepage` or `private` key, and it must |
| 13 | +# never gain one. The reason is a real incident, not a hypothetical: |
| 14 | +# |
| 15 | +# This file previously read `name: "{{REPO}}"`. probot/settings applies it on |
| 16 | +# every push to the default branch, so it submitted the literal string |
| 17 | +# `{{REPO}}` as the repository name. GitHub sanitises an invalid name by |
| 18 | +# collapsing each run of illegal characters to a dash — `{{REPO}}` became |
| 19 | +# `-REPO-`. The template renamed itself on every push, its old URL 404'd, and |
| 20 | +# it was mistaken for a deleted repository. `description` was likewise left |
| 21 | +# reading the literal `{{DESCRIPTION}}` on the live repo. |
| 22 | +# |
| 23 | +# Two properties make identity keys unsafe here specifically: |
| 24 | +# |
| 25 | +# 1. This is a TEMPLATE. `just repo-init` fills placeholders in repos minted by the |
| 26 | +# scaffolder — but GitHub's "Use this template" button copies the default |
| 27 | +# branch verbatim and never runs `just repo-init`. Any placeholder left in a |
| 28 | +# probot-managed file therefore reaches children unrendered. |
| 29 | +# 2. Identity is not shareable. The template must be public while children |
| 30 | +# default private; a child cannot inherit either `name` or `private` from |
| 31 | +# its parent without being wrong. |
| 32 | +# |
| 33 | +# Repository identity and visibility are therefore set OUT OF BAND: once per |
| 34 | +# repo, at creation time, by the operator (the Configure stage of ADR-0003). |
| 35 | +# `just repo-init` deliberately runs NO `gh` commands — it prints the exact |
| 36 | +# `gh repo edit` commands as next steps instead. Fail-closed default: repos |
| 37 | +# stay private unless the owner flips visibility deliberately; the template's |
| 38 | +# own name and visibility are set deliberately by the owner. |
| 39 | +# |
| 40 | +# Everything below is safe to inherit: it is true of every RSR repo regardless |
| 41 | +# of that repo's name, purpose or visibility. |
| 42 | +# |
| 43 | +# Enforced by `scripts/check-no-placeholders.sh`, which fails if this file |
| 44 | +# contains a `{{` token or declares any of the four identity keys. |
9 | 45 |
|
10 | 46 | # ─── Repository Settings ─────────────────────────────────────────────────────── |
11 | 47 |
|
12 | 48 | repository: |
13 | | - name: "echidna" |
14 | | - description: "ECHIDNA — Extensible Cognitive Hybrid Intelligence for Deductive Neural Assistance. Neurosymbolic theorem proving with 30 prover backends" |
15 | | - homepage: "https://github.com/hyperpolymath/echidna" |
16 | | - private: false |
17 | 49 | has_issues: true |
18 | 50 | has_projects: true |
19 | 51 | has_wiki: false |
|
0 commit comments