defaultbranch

package
v0.182.6 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 6, 2026 License: Apache-2.0 Imports: 24 Imported by: 0

Documentation

Overview

Package defaultbranch owns fleet policy inspection and durable mutation operations.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func HasFindings

func HasFindings(report Report) bool

func ValidDigest

func ValidDigest(value string) bool

Types

type Archive

type Archive struct {
	RepositoryID      int64  `json:"repository_id"`
	OriginalArchived  bool   `json:"original_archived"`
	InitialDefault    string `json:"initial_default"`
	DesiredDefault    string `json:"desired_default"`
	InitialHead       string `json:"initial_head"`
	FinalHead         string `json:"final_head,omitempty"`
	Phase             string `json:"phase"`
	UnarchiveAccepted bool   `json:"unarchive_accepted,omitempty"`
	RestoreAccepted   bool   `json:"restore_accepted,omitempty"`
	RecoveryRequired  bool   `json:"recovery_required,omitempty"`
	RestoreError      string `json:"restore_error,omitempty"`
	RecoveredFrom     string `json:"recovered_from,omitempty"`
	RecoveredSHA256   string `json:"recovered_sha256,omitempty"`
}

type Canonical

type Canonical struct {
	Path           string   `json:"path"`
	ObservedBranch string   `json:"observed_branch,omitempty"`
	RemoteHead     string   `json:"remote_head,omitempty"`
	Disposition    string   `json:"disposition"`
	Error          string   `json:"error,omitempty"`
	Actions        []string `json:"actions,omitempty"`
}

type Dependencies

type Dependencies struct {
	Persist          func(Report) error
	AuthUser         func() (string, error)
	MemberOrgs       func() ([]string, error)
	ListRemote       func(string) ([]discover.Repo, error)
	Read             func(ctx context.Context, endpoint string) ([]byte, error)
	Execute          func(ctx context.Context, args ...string) githubobserver.CommandResponse
	RenameWait       func(ctx context.Context, duration time.Duration) error
	RenameNow        func() time.Time
	ConfigPath       func() string
	Git              func(ctx context.Context, dir string, args ...string) (string, error)
	IsAncestor       func(ctx context.Context, dir, ancestor, descendant string) (bool, error)
	AtomicRenameRefs func(ctx context.Context, dir, source, destination, expected string) error
	AttachHead       func(ctx context.Context, dir, destination string) error
	RefExists        func(ctx context.Context, dir, ref string) (bool, error)
}

Dependencies are immutable bindings copied into one policy service.

type Options

type Options struct {
	Apply, IncludeUser, AllOrgs, TemporarilyUnarchive, MigratePagesSource, RewriteWorkflowTriggers bool
	Branch, ReportDir, ReconcileFrom, RestoreArchiveFrom                                           string
	ReconcileSHA256, RestoreArchiveSHA256                                                          string
	Owners, Repositories                                                                           []string
	Parallel                                                                                       int
}

type PagesSource

type PagesSource struct {
	BuildType string `json:"build_type"`
	Branch    string `json:"branch"`
	Path      string `json:"path"`
}

type Ref

type Ref struct {
	Commit struct {
		SHA string `json:"sha"`
	} `json:"commit"`
}

type RepoMetadata

type RepoMetadata struct {
	ID            int64  `json:"id"`
	DefaultBranch string `json:"default_branch"`
	Archived      bool   `json:"archived"`
	Fork          bool   `json:"fork"`
	Size          int    `json:"size"`
	Parent        *struct {
		FullName string `json:"full_name"`
	} `json:"parent"`
}

type Report

type Report struct {
	SchemaVersion int          `json:"schema_version"`
	Mode          string       `json:"mode"`
	Desired       string       `json:"desired"`
	Repositories  []Repository `json:"repositories"`
	Summary       Summary      `json:"summary"`
	ReportPath    string       `json:"report_path,omitempty"`
}

type Repository

type Repository struct {
	Repository      string       `json:"repository"`
	RepositoryID    int64        `json:"repository_id,omitempty"`
	ObservedDefault string       `json:"observed_default,omitempty"`
	VerifiedDefault string       `json:"verified_default,omitempty"`
	Desired         string       `json:"desired"`
	OldHead         string       `json:"old_head,omitempty"`
	NewHead         string       `json:"new_head,omitempty"`
	Disposition     string       `json:"disposition"`
	Error           string       `json:"error,omitempty"`
	Archived        bool         `json:"archived,omitempty"`
	Fork            bool         `json:"fork,omitempty"`
	TargetExists    bool         `json:"target_exists,omitempty"`
	RenameAccepted  bool         `json:"rename_accepted,omitempty"`
	RecoveredFrom   string       `json:"recovered_from,omitempty"`
	RecoveredSHA256 string       `json:"recovered_sha256,omitempty"`
	Archive         *Archive     `json:"archive_transition,omitempty"`
	PagesBefore     *PagesSource `json:"pages_before,omitempty"`
	PagesAfter      *PagesSource `json:"pages_after,omitempty"`
	PagesPhase      string       `json:"pages_phase,omitempty"`
	PagesAccepted   bool         `json:"pages_mutation_accepted,omitempty"`
	WorkflowFiles   []Workflow   `json:"workflow_files,omitempty"`
	WorkflowPhase   string       `json:"workflow_phase,omitempty"`
	WorkflowCommit  string       `json:"workflow_commit_oid,omitempty"`
	Impacts         []string     `json:"impacts,omitempty"`
	Actions         []string     `json:"actions,omitempty"`
	CanonicalClones []Canonical  `json:"canonical_clones,omitempty"`
}

type Request

type Request struct {
	Scope
	Options
}

type Scope

type Scope struct{ ProjectsRoot, Filter string }

type Service

type Service struct {
	// contains filtered or unexported fields
}

func New

func New() *Service

func (*Service) Run

func (service *Service) Run(ctx context.Context, request Request, progress io.Writer) (Report, error)

type Summary

type Summary struct {
	Inspected        int `json:"inspected"`
	Compliant        int `json:"compliant"`
	Drift            int `json:"drift"`
	Blocked          int `json:"blocked"`
	Errors           int `json:"errors"`
	Applied          int `json:"applied"`
	CanonicalBlocked int `json:"canonical_blocked"`
	CanonicalErrors  int `json:"canonical_errors"`
}

type Workflow

type Workflow struct {
	Path         string `json:"path"`
	BlobBefore   string `json:"blob_before"`
	SHA256Before string `json:"sha256_before"`
	SHA256After  string `json:"sha256_after"`
	// contains filtered or unexported fields
}

defaultBranchWorkflow records a byte-preserving proposed replacement. The contents themselves never enter a report: the before/after SHA-256 values bind the report to the exact bytes that were read and verified.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL