fix: omit repo-level web_commit_signoff_required when org-enforced - #96
Merged
Merged
Conversation
GitHub returns 422 "Commit signoff is enforced by the organization and cannot be disabled" on ANY repo-level write of web_commit_signoff_required once the org enforces it — aborting the repo apply before its rulesets/branch config are created, so every new repo failed to get governed. Resolve the repo-level value to null (omit) when the org enforces it, else respect the repo level (explicit YAML value, or the null default). Org enforcement is the single source of truth. Fixes the 422 that left nwarila-platform/secure-wazuh without rulesets/CODEOWNERS.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
GitHub 422s
Commit signoff is enforced by the organization and cannot be disabledon ANY repo-level write ofweb_commit_signoff_requiredonce the org enforces it — which aborted the repo apply before rulesets/branch config were created. Every new repo hit this (it left nwarila-platform/secure-wazuh with no rulesets/CODEOWNERS).Resolve the repo-level value to
null(omit) when the org enforces it, else respect the repo level (explicit YAML value, or the null default). Org enforcement is the single source of truth; a repo may still set it explicitly.30-locals.tf: conditional omit (null-safe for personal mode).