Skip to content

Allow hyphens in annotation names - #3443

Merged
migmartri merged 1 commit into
chainloop-dev:mainfrom
wangyusheng1985:repo-agent/5ef59633-3405
Sep 29, 2026
Merged

migmartri merged 1 commit into
chainloop-dev:mainfrom
wangyusheng1985:repo-agent/5ef59633-3405

Conversation

@wangyusheng1985

@wangyusheng1985 wangyusheng1985 commented Sep 15, 2026 •

Copy link
Copy Markdown
Contributor

Annotation names were limited to word characters, so values like my-annotation were rejected even though contract and material names already allow hyphens.

This widens the Annotation.name validation pattern to accept hyphens while remaining additive for existing underscore and alphanumeric names. Generated protobuf, TypeScript, and JSON Schema artifacts are updated to match, and hyphenated names continue to work through dependency-track interpolation and filter matching.

Assisted-by: Claude Code

Validation observed for this change:

  • gofmt -l app/controlplane/api/workflowcontract/v1/crafting_schema_test.go app/controlplane/plugins/core/dependency-track/v1/extension_test.go
  • go test ./app/controlplane/api/workflowcontract/v1/ ./app/controlplane/plugins/core/dependency-track/v1/ -count=1 -run 'TestValidateAnnotations|TestAnnotationNameConstraintAllowsHyphen|TestResolveProjectName|TestVerifyAllFilters'

Fixes #3405

Review in cubic

@wangyusheng1985
wangyusheng1985 marked this pull request as ready for review September 15, 2026 11:42
@chainloop-platform

chainloop-platform Bot commented Sep 15, 2026 •

Copy link
Copy Markdown
Contributor

AI Session Checks — ⏭️ bypassed by label

AI Coding Session Check Bypassed

This PR carries the skip-ai-session label, so the AI coding session check was bypassed.

Learn more about Chainloop Trace.


Security Checks — ✅ 6 passing

✅ secret-scan

Status Policy Messages
✅ Passed secrets-detection -

✅ sast-scan

Status Policy Messages
✅ Passed owasp-top10-2025 -
✅ Passed sast -
✅ Passed cwe-top25 -
✅ Passed cwe-top26-40-cusp -

✅ iac-scan

Status Policy Messages
✅ Passed iac-misconfiguration -

✅ security-context — no advisories

Nothing this change touches has a recorded security-fix history.

View security context ↗ · Security context documentation ↗

⏭️ 2 scans not applied

Scan Reason
vulnerability-scan no manifest/lockfile changed
github-actions-scan no workflow files changed

View attestation ↗


PR validation — ✅ 3 passing

Status Policy Material Messages
✅ Passed pr-min-approvals pr-info -
✅ Passed pr-description-required pr-info -
✅ Passed pr-user-story-linked pr-info -

View attestation ↗


Powered by Chainloop and Chainloop Trace

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 7 files

Re-trigger cubic

@migmartri

Copy link
Copy Markdown
Member

Cam you please sign the commit? Thanks!

@wangyusheng1985

Copy link
Copy Markdown
Contributor Author

Do you mean a cryptographic commit signature or a DCO Signed-off-by trailer? Please point me to the applicable contribution policy.

@migmartri

Copy link
Copy Markdown
Member

Do you mean a cryptographic commit signature or a DCO Signed-off-by trailer? Please point me to the applicable contribution policy.

Both, https://github.com/chainloop-dev/chainloop/blob/main/CONTRIBUTING.md#commit-format

Thanks

@migmartri
migmartri requested a review from a team September 18, 2026 07:57
@migmartri

Copy link
Copy Markdown
Member

can you please sign the commit? otherwise we'd need to close the issue, thanks!

Signed-off-by: wangyusheng1985 <wangyusheng1985@users.noreply.github.com>
@migmartri
migmartri merged commit 4b07a6d into chainloop-dev:main Sep 29, 2026
17 checks passed
@migmartri

Copy link
Copy Markdown
Member

Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Allow hyphens in annotation names

2 participants