Commits reference a work item
git/work-item-reference@v1
Every commit in the build range, or the branch it is on, references the change record it belongs to.
| Id | git/work-item-reference |
| Version | v1 |
| Category | git |
| Default severity | warning |
| Interpreter | python3 |
| Timeout | 30 seconds |
| Violations tolerated | 0 |
| Collects | git |
Collectors
This guardrail doesn't gather anything itself. It relies on the collectors below, which the CLI runs once per build before any check, and reads what they found from GUARDRAIL_FACTS. If a collector collects nothing, this guardrail is skipped, not failed.
| Collector | Gathers | Inputs it is given |
|---|---|---|
git | The repository, HEAD, the remotes, and every commit between the base ref and HEAD with its message, author, parents, and the files the range changed with the lines it added and removed to each. | baseRef |
The inputs above are this guardrail's own inputs, passed straight through to the collector. Setting one in buildnote.json changes what is collected, and two guardrails configured the same way share a single collection.
Configuration
{
"guardrails": {
"failOn": "error",
"checks": [
{
"use": "git/work-item-reference@v1",
"severity": "warning",
"with": {
"baseRef": "origin/main",
"pattern": "[A-Z][A-Z0-9]+-[0-9]+",
"allowBranch": "true"
},
"exemptions": []
}
]
}
}Inputs
| Input | Description | Default | Environment variable |
|---|---|---|---|
baseRef | Ref the range starts at. The commits checked are <baseRef>..HEAD. | origin/main | GUARDRAIL_INPUT_BASEREF |
pattern | Regular expression a work item reference must match. The default matches Jira keys; use #[0-9]+ for GitHub issues. | [A-Z][A-Z0-9]+-[0-9]+ | GUARDRAIL_INPUT_PATTERN |
allowBranch | Whether a reference in the branch name covers every commit on it. | true | GUARDRAIL_INPUT_ALLOWBRANCH |
How to fix
Put the ticket key in the commit subject or body, or in the branch name:
feat(ledger): round half to even on settlement
Refs: COMPANY-1423When auditors test change management, they sample production changes and ask to see the approved record behind each one. A commit that can't be linked to a record is the finding, whatever the record says.
More in git
git/author-identity-domain. Every commit in the build range was authored and committed with an email address on a domain your organisation controls.git/changed-files-budget. The build range changes few enough files that a reviewer can hold the whole change in their head.git/changed-lines-budget. The build range adds and removes few enough lines that a reviewer can read the whole change before approving it.git/conventional-commits. Every commit message in the build range follows the Conventional Commits specification, including the subject line, the blank line before the body, and the BREAKING CHANGE footer.git/no-merge-commits. The build range contains no merge commits.git/no-wip-commits. The build range contains no commit whose subject says it was never meant to be merged.