Allow hyphens in annotation names - #3443
Conversation
AI Session Checks — ⏭️ bypassed by labelAI Coding Session Check BypassedThis PR carries the Learn more about Chainloop Trace. Security Checks — ✅ 6 passing✅
|
| Status | Policy | Messages |
|---|---|---|
| ✅ Passed | secrets-detection |
- |
✅ sast-scan
| Status | Policy | Messages |
|---|---|---|
| ✅ Passed | owasp-top10-2025 |
- |
| ✅ Passed | sast |
- |
| ✅ Passed | cwe-top25 |
- |
| ✅ Passed | cwe-top26-40-cusp |
- |
✅ iac-scan
| Status | Policy | Messages |
|---|---|---|
| ✅ Passed | iac-misconfiguration |
- |
✅ security-context — no advisories
Nothing this change touches has a recorded security-fix history.
View security context ↗ · Security context documentation ↗
⏭️ 2 scans not applied
| Scan | Reason |
|---|---|
vulnerability-scan |
no manifest/lockfile changed |
github-actions-scan |
no workflow files changed |
PR validation — ✅ 3 passing
| Status | Policy | Material | Messages |
|---|---|---|---|
| ✅ Passed | pr-min-approvals |
pr-info |
- |
| ✅ Passed | pr-description-required |
pr-info |
- |
| ✅ Passed | pr-user-story-linked |
pr-info |
- |
Powered by Chainloop and Chainloop Trace
|
Cam you please sign the commit? Thanks! |
|
Do you mean a cryptographic commit signature or a DCO Signed-off-by trailer? Please point me to the applicable contribution policy. |
Both, https://github.com/chainloop-dev/chainloop/blob/main/CONTRIBUTING.md#commit-format Thanks |
|
can you please sign the commit? otherwise we'd need to close the issue, thanks! |
Signed-off-by: wangyusheng1985 <wangyusheng1985@users.noreply.github.com>
929f3d9 to
cc7e208
Compare
|
Thanks! |
Annotation names were limited to word characters, so values like
my-annotationwere rejected even though contract and material names already allow hyphens.This widens the Annotation.name validation pattern to accept hyphens while remaining additive for existing underscore and alphanumeric names. Generated protobuf, TypeScript, and JSON Schema artifacts are updated to match, and hyphenated names continue to work through dependency-track interpolation and filter matching.
Assisted-by: Claude Code
Validation observed for this change:
gofmt -l app/controlplane/api/workflowcontract/v1/crafting_schema_test.go app/controlplane/plugins/core/dependency-track/v1/extension_test.gogo test ./app/controlplane/api/workflowcontract/v1/ ./app/controlplane/plugins/core/dependency-track/v1/ -count=1 -run 'TestValidateAnnotations|TestAnnotationNameConstraintAllowsHyphen|TestResolveProjectName|TestVerifyAllFilters'Fixes #3405