Skip to content

feat(.github): score community-namespace modules in PR scorecard checks - #1069

Merged
bpmct merged 1 commit into
mainfrom
bpmct/scorecard-all-namespaces
Aug 20, 2026
Merged

feat(.github): score community-namespace modules in PR scorecard checks#1069
bpmct merged 1 commit into
mainfrom
bpmct/scorecard-all-namespaces

Conversation

@bpmct

@bpmct bpmct commented Aug 20, 2026

Copy link
Copy Markdown
Member

Follow-up to #1065. The /scorecard command runs now, but only looks at registry/coder/modules, so community-namespace PRs like #1068 report "no changed modules" and get no comment.

This makes the PR scorecard check work for modules in any namespace (registry/<namespace>/modules/<name>). Module specs are now namespace/name, with bare names still meaning the coder namespace.

Discussions are still coder-only:

  • Community modules skip the baseline lookup and always report a standalone advisory score, with report text that says so (no "discussion is created after merge" for them).
  • The discussion-writing runs (post-merge, weekly) enumerate registry/coder/modules only, unchanged.
  • The script now refuses non-coder specs outside --pr-report/--dry-run, so a community discussion can't be created by accident.

🤖 Generated with Coder Agents on behalf of @bpmct

@bpmct
bpmct merged commit 77ee11d into main Aug 20, 2026
6 checks passed
@bpmct
bpmct deleted the bpmct/scorecard-all-namespaces branch August 20, 2026 19:37
bpmct added a commit that referenced this pull request Aug 20, 2026
…dule content (#1070)

Follow-up to #1069. The `/scorecard` run on #1068 detected
`droopy4096/mise-install` correctly but failed at the materialize step:

```
error: pathspec 'registry/*/modules' did not match any file(s) known to git
```

Wildcard pathspecs don't directory-prefix match the way literal paths
do, so `registry/*/modules` matched nothing. Fixed by overlaying the
whole `registry/` tree instead, which is simpler and equally safe: it's
all inert data read as text for the scoring prompt, and everything under
`.github/` stays at the trusted base.

Verified locally against `refs/pull/1068/merge`: the checkout now
materializes `registry/droopy4096/modules/mise-install`.

🤖 Generated with Coder Agents on behalf of @bpmct
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants