Commits reference a work item
git/work-item-reference@v1
Every commit in the build range, or the branch it is on, names the change record it belongs to.
| Id | git/work-item-reference |
| Version | v1 |
| Category | git |
| Default severity | warning |
| Interpreter | python3 |
| Timeout | 30 seconds |
| Violations tolerated | 0 |
| Collects | git |
Collectors
This guardrail gathers nothing itself. It depends on the collectors below, which the CLI runs once per build before any check, and reads what they found out of GUARDRAIL_FACTS. A collector that collects nothing skips this guardrail rather than failing it.
| Collector | Gathers | Inputs it is given |
|---|---|---|
git | The repository, HEAD, the remotes, and every commit between the base ref and HEAD with its message, author, parents and the files the range changed. | baseRef |
The inputs above are this guardrail's own, passed straight through. Configuring one in buildnote.json changes what is collected, and two guardrails configured the same way share the one collection.
Configuration
{
"guardrails": {
"failOn": "error",
"comment": true,
"checks": [
{
"use": "git/work-item-reference@v1",
"severity": "warning",
"with": {
"baseRef": "origin/main",
"pattern": "[A-Z][A-Z0-9]+-[0-9]+",
"allowBranch": "true"
},
"exemptions": []
}
]
}
}Inputs
| Input | Description | Default | Environment variable |
|---|---|---|---|
baseRef | Ref the range starts at. The commits checked are <baseRef>..HEAD. | origin/main | GUARDRAIL_INPUT_BASEREF |
pattern | Regular expression a work item reference matches. The default is the Jira key shape; use #[0-9]+ for GitHub issues. | [A-Z][A-Z0-9]+-[0-9]+ | GUARDRAIL_INPUT_PATTERN |
allowBranch | Whether a reference in the branch name covers every commit on it. | true | GUARDRAIL_INPUT_ALLOWBRANCH |
How to fix
Put the ticket key in the commit subject or body, or in the branch name:
feat(ledger): round half to even on settlement
Refs: ACME-1423An auditor testing change management samples production changes and asks to see the approved record behind each one. A commit nobody can join to a record is the finding, whatever the record says.
More in git
git/author-identity-domain. Every commit in the build range was authored and committed by an address on a domain the organisation controls.git/changed-files-budget. The build range changes few enough files that a reviewer can hold the whole change in their head.git/conventional-commits. Every commit message in the build range follows the Conventional Commits specification: the subject line, the blank line before the body, and the BREAKING CHANGE footer.git/no-merge-commits. The build range contains no merge commits.git/no-wip-commits. The build range carries no commit that says it was never meant to be merged.