Skip to content

chore: harden the template for derived repositories - #146

Merged
cuioss-oliver merged 3 commits into
mainfrom
chore/template-hardening
Sep 24, 2026
Merged

cuioss-oliver merged 3 commits into
mainfrom
chore/template-hardening

Conversation

@cuioss-oliver

@cuioss-oliver cuioss-oliver commented Sep 24, 2026 •

Copy link
Copy Markdown
Collaborator

Stacked on #145. Merge #145 first, then retarget this PR to main. This PR changes release.current-version; without #145's template-repository exclusion, merging it would publish cui-java-module-template 0.1.0 to Maven Central.

Summary

Lessons from bootstrapping plan-marshall-mcp from this template:

Release safeguards

  • release.current-version 1.0.0 → 0.1.0 (pom 0.1.0-SNAPSHOT, next 0.1.1-SNAPSHOT), with a warning comment. A derived repository never has to touch the value. plan-marshall-mcp changed it while customizing, which published its 0.1.0 by accident. The first release is now a deliberate dispatch.
  • New .claude/skills/release/SKILL.md, a generic runbook derived from API-Sheriff and plan-marshall-mcp. It covers:
    • the two release paths
    • the checks before the cut: trigger, tag, Central, green main, quiesced queue
    • the exactly-one verification after it
    • the release-notes format
  • Release rules added to CLAUDE.md and to a new README section, Releasing.

customize.sh fixes (verified on a scratch copy with custom values; the result builds with ./mvnw verify)

  • The project.yml keys pages-reference: and sonar-project-key: never matched the file (reference: / project-key:). Fixed; the description is now set too.
  • The script replaced <n>, which the POM doesn't have, so <name> was never set.
  • Renaming the module also rewrote exports to the module name. The package stays de.cuioss.template, so the result didn't compile. The script now keeps it.
  • Removed the step for SECURITY.md, which doesn't exist here.
  • CLAUDE.md and the runbook get the repository slug.
  • The script never touches release.yml (template exclusion) or current-version.
  • It ends with the next steps.

Org and setup

  • README: an After creating the repository checklist:
    • add the repository to consumers: in cuioss-organization
    • apply repo-settings and branch-protection
    • SonarCloud: rename master → main before the first analysis, and expect a quality gate of NONE once
  • Corrected the secrets note: the callers pass secrets explicitly and must pass only declared ones.
  • maven.yml also builds release/* pushes, like the org example.
  • .gitignore: plan-marshall .plan/ block, .factorypath.
  • dependabot.yml: adds a github-actions lane for third-party actions. The org workflow pins stay with the cuioss-release-bot; Dependabot doesn't bump them, so the two don't compete.

The baseline stays at Java 21.

Test plan

  • customize.sh on a scratch copy: all keys replaced; current-version and the release.yml literal untouched; ./mvnw verify green
  • CI green

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @cuioss-oliver, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 2 hours and 3 minutes by commenting @sourcery-ai review. Upgrade to get a review now.

@coderabbitai

coderabbitai Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 17 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository: cuioss/coderabbit/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: e4538313-f316-4dad-ac69-a271e70a20a6

📥 Commits

Reviewing files that changed from the base of the PR and between 91a4560 and df5718e.

📒 Files selected for processing (10)
  • .claude/skills/release/SKILL.md
  • .github/dependabot.yml
  • .github/project.yml
  • .github/workflows/maven.yml
  • .gitignore
  • CLAUDE.md
  • README.adoc
  • customization.properties
  • customize.sh
  • pom.xml

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@cuioss-oliver
cuioss-oliver force-pushed the chore/template-hardening branch from 911cfd1 to b326ded Compare September 24, 2026 09:12
Base automatically changed from chore/release-guard to main September 24, 2026 09:34
cuioss-oliver and others added 3 commits September 24, 2026 11:34
- release.current-version 1.0.0 -> 0.1.0 (pom 0.1.0-SNAPSHOT): a derived
  repository never has to change it, its first release is a deliberate
  dispatch. Changing it while customizing published plan-marshall-mcp 0.1.0.
- release runbook .claude/skills/release/SKILL.md (from API-Sheriff /
  plan-marshall-mcp), release rules in CLAUDE.md and README
- customize.sh: fix the project.yml keys (pages reference, sonar
  project-key never matched), set description, set <name> (matched <n>),
  keep the exported package (renaming it broke the build), drop the
  missing SECURITY.md, never touch release.yml / current-version
- README: after-creation checklist (org consumers list, branch protection,
  SonarCloud master->main rename, first quality gate NONE), secrets note
- maven.yml builds release/* pushes like the org example; .gitignore
  plan-marshall block; dependabot note on the github-actions lane

Co-Authored-By: plan-marshall <noreply@cuioss.de>
…r the triggers

Co-Authored-By: plan-marshall <noreply@cuioss.de>
The cuioss-organization pins are bumped by the release bot, not by
Dependabot, so the lane does not compete; it covers any third-party
action a derived repository adds.

Co-Authored-By: plan-marshall <noreply@cuioss.de>
@cuioss-oliver
cuioss-oliver force-pushed the chore/template-hardening branch from bf692e0 to df5718e Compare September 24, 2026 09:35
@cuioss-oliver
cuioss-oliver merged commit 65a85e1 into main Sep 24, 2026
24 checks passed
@cuioss-oliver
cuioss-oliver deleted the chore/template-hardening branch September 24, 2026 09:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant