Repository navigation
chore: harden the template for derived repositories - #146
Conversation
There was a problem hiding this comment.
Sorry @cuioss-oliver, you've used your own review budget of 250,000 diff characters for the last 7 days.
You can request another review in 2 hours and 3 minutes by commenting @sourcery-ai review. Upgrade to get a review now.
|
Warning Review limit reachedNext included review available in 17 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Repository: cuioss/coderabbit/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (10)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
911cfd1 to
b326ded
Compare
- release.current-version 1.0.0 -> 0.1.0 (pom 0.1.0-SNAPSHOT): a derived repository never has to change it, its first release is a deliberate dispatch. Changing it while customizing published plan-marshall-mcp 0.1.0. - release runbook .claude/skills/release/SKILL.md (from API-Sheriff / plan-marshall-mcp), release rules in CLAUDE.md and README - customize.sh: fix the project.yml keys (pages reference, sonar project-key never matched), set description, set <name> (matched <n>), keep the exported package (renaming it broke the build), drop the missing SECURITY.md, never touch release.yml / current-version - README: after-creation checklist (org consumers list, branch protection, SonarCloud master->main rename, first quality gate NONE), secrets note - maven.yml builds release/* pushes like the org example; .gitignore plan-marshall block; dependabot note on the github-actions lane Co-Authored-By: plan-marshall <noreply@cuioss.de>
…r the triggers Co-Authored-By: plan-marshall <noreply@cuioss.de>
The cuioss-organization pins are bumped by the release bot, not by Dependabot, so the lane does not compete; it covers any third-party action a derived repository adds. Co-Authored-By: plan-marshall <noreply@cuioss.de>
bf692e0 to
df5718e
Compare
Stacked on #145. Merge #145 first, then retarget this PR to
main. This PR changesrelease.current-version; without #145's template-repository exclusion, merging it would publishcui-java-module-template0.1.0 to Maven Central.Summary
Lessons from bootstrapping
plan-marshall-mcpfrom this template:Release safeguards
release.current-version1.0.0→0.1.0(pom0.1.0-SNAPSHOT, next0.1.1-SNAPSHOT), with a warning comment. A derived repository never has to touch the value.plan-marshall-mcpchanged it while customizing, which published its 0.1.0 by accident. The first release is now a deliberate dispatch..claude/skills/release/SKILL.md, a generic runbook derived from API-Sheriff and plan-marshall-mcp. It covers:main, quiesced queueCLAUDE.mdand to a new README section, Releasing.customize.shfixes (verified on a scratch copy with custom values; the result builds with./mvnw verify)project.ymlkeyspages-reference:andsonar-project-key:never matched the file (reference:/project-key:). Fixed; thedescriptionis now set too.<n>, which the POM doesn't have, so<name>was never set.exportsto the module name. The package staysde.cuioss.template, so the result didn't compile. The script now keeps it.SECURITY.md, which doesn't exist here.CLAUDE.mdand the runbook get the repository slug.release.yml(template exclusion) orcurrent-version.Org and setup
consumers:in cuioss-organizationrepo-settingsandbranch-protectionmaster→mainbefore the first analysis, and expect a quality gate ofNONEoncemaven.ymlalso buildsrelease/*pushes, like the org example..gitignore: plan-marshall.plan/block,.factorypath.dependabot.yml: adds a github-actions lane for third-party actions. The org workflow pins stay with the cuioss-release-bot; Dependabot doesn't bump them, so the two don't compete.The baseline stays at Java 21.
Test plan
customize.shon a scratch copy: all keys replaced;current-versionand therelease.ymlliteral untouched;./mvnw verifygreen