Repository navigation
Unify ospo-actions configuration #74
Copy link
Copy link
Open
Labels
enhancementNew feature or requestNew feature or requestospo-actionsIssues relating to the OSPO ActionsIssues relating to the OSPO Actions
Description
Activity
- converted this from a draft issue
on Mar 18, 2024 - addedospo-actionsIssues relating to the OSPO ActionsIssues relating to the OSPO Actions
on Mar 19, 2024 I like this idea.
A thought and a couple questions:
Thought:
- a central
~/.githubospo(not married to the name) file that has all the contents from each repositories.env-sampleor README environment variables (some are not in the samples currently) in there. Like asked above, if exists, it will be used and then fall back to repo directory.envfile.
Questions:
- you mean this from a contributor's perspective, correct? When a developer is working on a pull request locally each action could look for the "centralized" environment variable file and use it if it exists, otherwise fall back to the repo's
.envfile. I ask this because when the actions run they will be told where the environment variables are located, usually in repo secrets (e.g,${{ secrets.GH_APP_ID }}) - do we want to do one or the other regarding parsing (either
~/.githubospoorrepo_dir/.env)? Or do we parse from both. I prefer the former, easier to manage. Otherwise you have to set expectation on presidence re: overwrites (i.e,GH_APP_IDis in~/.githubospoand also inrepo_dir/.env, which has presidence?)
- a central
I'm also looking at possibly doing a composite GitHub action for env handling https://docs.github.com/en/actions/creating-actions/creating-a-composite-action
Reacted by leliahttps://docs.github.com/en/actions/creating-actions/creating-a-composite-action
I'd definitely be in support of this!
Reacted by Jason Meridthdanytorres8080oo-commits commented
on Oct 3, 2025 on Oct 3, 2025 · Hidden as spamshow commentMore actionsdanytorres8080oo-commits commented
on Oct 3, 2025 on Oct 3, 2025 · Hidden as spamshow commentMore actions
Metadata
Metadata
Assignees
Labels
enhancementNew feature or requestNew feature or requestospo-actionsIssues relating to the OSPO ActionsIssues relating to the OSPO Actions
Type
Projects
- StatusShow more project fieldsBacklog
Currently, the various ospo actions are completely independent. But users who adopt several of them end up restating a lot of configuration for them which would ideally be centralized. As concrete examples, setting:
would be better served by a common configuration file that all of the actions know to look for.