Skip to content

Commit bde112f

Browse files
chore(governance): stop declaring repository identity in settings.yml (#62)
`probot/settings` applies this file on **every push to the default branch**, so the four identity keys it declared are instructions, not documentation. The estate has already paid for exactly this: `.github/settings.yml` once read `name: "{{REPO}}"`, GitHub collapsed the illegal braces to dashes, the repository renamed itself to `-REPO-` on every push, its old URL 404'd, and it was read as a deleted repository. This repo still declared `name`, `description`, `homepage` and `private`. The repair is convergence on the source of truth, not new content: - the header becomes the template's own header, which documents the incident and the rule ("THIS FILE MUST NEVER DECLARE REPOSITORY IDENTITY"); - the four identity keys are removed; **everything else is unchanged** — same repository settings, same 18 labels; - repository identity and visibility stay set out of band, once, by the owner. Verified with the estate's own gate, `scripts/check-no-placeholders.sh`, whose settings.yml guard runs in template repos too (that exemption is how the original incident went unseen). On this branch the guard reports clean.
1 parent 960716f commit bde112f

1 file changed

Lines changed: 35 additions & 5 deletions

File tree

.github/settings.yml

Lines changed: 35 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -7,15 +7,45 @@
77
# applied by the probot/settings app when changes are pushed to the default
88
# branch. Install the app at: https://github.com/apps/settings
99
#
10-
# Template file — replace jaffascript and JavaScript/TypeScript-syntax AffineScript — affine resource guarantees + typed-wasm output for JS/TS-shaped code with actual values.
10+
# ─── THIS FILE MUST NEVER DECLARE REPOSITORY IDENTITY ─────────────────────────
11+
#
12+
# It carries NO `name`, `description`, `homepage` or `private` key, and it must
13+
# never gain one. The reason is a real incident, not a hypothetical:
14+
#
15+
# This file previously read `name: "{{REPO}}"`. probot/settings applies it on
16+
# every push to the default branch, so it submitted the literal string
17+
# `{{REPO}}` as the repository name. GitHub sanitises an invalid name by
18+
# collapsing each run of illegal characters to a dash — `{{REPO}}` became
19+
# `-REPO-`. The template renamed itself on every push, its old URL 404'd, and
20+
# it was mistaken for a deleted repository. `description` was likewise left
21+
# reading the literal `{{DESCRIPTION}}` on the live repo.
22+
#
23+
# Two properties make identity keys unsafe here specifically:
24+
#
25+
# 1. This is a TEMPLATE. `just repo-init` fills placeholders in repos minted by the
26+
# scaffolder — but GitHub's "Use this template" button copies the default
27+
# branch verbatim and never runs `just repo-init`. Any placeholder left in a
28+
# probot-managed file therefore reaches children unrendered.
29+
# 2. Identity is not shareable. The template must be public while children
30+
# default private; a child cannot inherit either `name` or `private` from
31+
# its parent without being wrong.
32+
#
33+
# Repository identity and visibility are therefore set OUT OF BAND: once per
34+
# repo, at creation time, by the operator (the Configure stage of ADR-0003).
35+
# `just repo-init` deliberately runs NO `gh` commands — it prints the exact
36+
# `gh repo edit` commands as next steps instead. Fail-closed default: repos
37+
# stay private unless the owner flips visibility deliberately; the template's
38+
# own name and visibility are set deliberately by the owner.
39+
#
40+
# Everything below is safe to inherit: it is true of every RSR repo regardless
41+
# of that repo's name, purpose or visibility.
42+
#
43+
# Enforced by `scripts/check-no-placeholders.sh`, which fails if this file
44+
# contains a `{{` token or declares any of the four identity keys.
1145

1246
# ─── Repository Settings ───────────────────────────────────────────────────────
1347

1448
repository:
15-
name: "jaffascript"
16-
description: "JavaScript/TypeScript-syntax AffineScript — affine resource guarantees + typed-wasm output for JS/TS-shaped code"
17-
homepage: "https://github.com/hyperpolymath/jaffascript"
18-
private: false
1949
has_issues: true
2050
has_projects: true
2151
has_wiki: false

0 commit comments

Comments
 (0)