Skip to content
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
Show all changes
43 commits
Select commit Hold shift + click to select a range
c512861
Extend `UserConfig` type to be aware of Default Setup properties
mbg Jul 3, 2026
cd604f8
Refactor `determineUserConfig` out of `initConfig`
mbg Jul 3, 2026
a52a966
Add `mergeUserConfigs` with tests
mbg Jul 3, 2026
132634d
Add FF for configuration merging
mbg Jul 6, 2026
53a488c
Add JSDoc for `loadUserConfig`
mbg Jul 6, 2026
6860cc1
Move `validateConfig` FF query
mbg Jul 6, 2026
0188f39
Add unit tests for existing behaviour of `determineUserConfig`
mbg Jul 6, 2026
d1db924
Allow `env` input for relevant functions in `actions-util.ts`
mbg Jul 6, 2026
18d20b7
Allow setting environment variables
mbg Jul 6, 2026
3157774
Give `determineUserConfig` access to the environment
mbg Jul 6, 2026
42c0c6a
Allow merging Default Setup `config` with config file
mbg Jul 6, 2026
3707b44
Document that `inputs` might be mutated
mbg Jul 6, 2026
d149f93
Return `mergedConfig` instead of loading it again
mbg Jul 6, 2026
764f470
Test `inputs.configFile` mutation in tests
mbg Jul 6, 2026
9a06fa6
Set the required `workspacePath` input
mbg Jul 6, 2026
44d6b3b
Initialise `env` in `actions-util` when not provided
mbg Jul 6, 2026
4509fb3
Fix JSDoc for `determineUserConfig`
mbg Jul 6, 2026
8476401
Make lazy FF check less ambiguous
mbg Jul 6, 2026
8be707b
Merge remote-tracking branch 'origin/main' into mbg/config/merge
mbg Jul 6, 2026
7ccd988
Merge branch 'main' into mbg/config/merge
mbg Jul 8, 2026
06898d7
Rename `mergeUserConfigs`
mbg Jul 8, 2026
d2472aa
Merge remote-tracking branch 'origin/main' into mbg/config/merge
mbg Jul 9, 2026
6829d6c
Remove obsolete JSDoc parameter for `loadUserConfig`
mbg Jul 9, 2026
6973946
Check file on disk and mutated inputs
mbg Jul 9, 2026
dc2d916
Add `checkSchema` function
mbg Jul 9, 2026
1f91ec8
Add an `array` `Validator`
mbg Jul 9, 2026
98dbd66
Add an `object` `Validator`
mbg Jul 9, 2026
9573f05
Improve type inference for `object` and `validateSchema`
mbg Jul 9, 2026
847e7af
Log warning for unrecognised keys in Default Setup config
mbg Jul 9, 2026
7c961fa
Add diagnostic for unrecognised keys
mbg Jul 9, 2026
cee0056
Allow nested checking
mbg Jul 9, 2026
e4752e7
Remove keys from unrecognised set as soon as found
mbg Jul 10, 2026
8d8f054
Add convenience functions to produce `CheckSchemaResult` values
mbg Jul 10, 2026
512bf6f
Track invalid keys, and use more standard JSON path notation
mbg Jul 10, 2026
0b10dee
Propagate `CheckSchemaOptions` to allow `failFast` to work as intended
mbg Jul 10, 2026
e26215c
fixup! Track invalid keys, and use more standard JSON path notation
mbg Jul 10, 2026
26cbf9f
Don't include nested keys that are unknown
mbg Jul 10, 2026
f630f8f
Report invalid keys separately
mbg Jul 10, 2026
66c15f4
Merge remote-tracking branch 'origin/main' into mbg/config/merge
mbg Jul 13, 2026
2773684
Update test for changed test API
mbg Jul 13, 2026
f181d70
Update `determineUserConfig` tests to use new framework
mbg Jul 13, 2026
7577328
Return function result from `passes` alongside assertion result
mbg Jul 13, 2026
3d2713f
Merge remote-tracking branch 'origin/main' into mbg/config/merge
mbg Jul 14, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
Add mergeUserConfigs with tests
  • Loading branch information
mbg committed Jul 6, 2026
commit a52a9662e9ed59dcf5726c3eb40ba4a85db8535a
65 changes: 65 additions & 0 deletions src/config/db-config.test.ts
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,7 @@ import {
getRecordingLogger,
LoggedMessage,
makeMacro,
RecordingLogger,
} from "../testing-utils";
import { ConfigurationError, prettyPrintPack } from "../util";

Expand Down Expand Up @@ -488,3 +489,67 @@ test("parseUserConfig - throws no ConfigurationError if validation should fail,
),
);
});

test("mergeUserConfigs - combines threat models", async (t) => {
const logger = new RecordingLogger();
const result = dbConfig.mergeUserConfigs(
logger,
{ "threat-models": ["a", "b"] },
{ "threat-models": ["local", "remote"] },
);

const threatModels = result["threat-models"];

if (t.truthy(threatModels)) {
t.deepEqual(threatModels, ["a", "b", "local", "remote"]);
}
Comment thread
mbg marked this conversation as resolved.
});

test("mergeUserConfigs - warns if user-supplied config contains default setup key", async (t) => {
const logger = new RecordingLogger();
const result = dbConfig.mergeUserConfigs(logger, {}, { "default-setup": {} });

// User-supplied value is ignored.
t.deepEqual(result, {});

// Warning is logged.
t.true(
logger.hasMessage(
"The 'default-setup' configuration key is not supported in user-supplied configuration files",
),
);
});

test("mergeUserConfigs - keeps default setup key from 'config' input", async (t) => {
const logger = new RecordingLogger();
const expected: dbConfig.DefaultSetupConfig = {
org: { "model-packs": ["some-pack"] },
};
const result = dbConfig.mergeUserConfigs(
logger,
{ "default-setup": expected },
{},
);

// Result matches the input.
t.deepEqual(result["default-setup"], expected);

// No warning is logged.
t.false(
logger.hasMessage(
"The 'default-setup' configuration key is not supported in user-supplied configuration files",
),
);
});

test("mergeUserConfigs - keeps other properties from user-supplied configuration", async (t) => {
const logger = new RecordingLogger();
const configFile: dbConfig.UserConfig = {
"query-filters": [{ exclude: { a: "b" } }],
"paths-ignore": ["path"],
};

const result = dbConfig.mergeUserConfigs(logger, {}, configFile);

t.deepEqual(result, configFile);
});
50 changes: 50 additions & 0 deletions src/config/db-config.ts
Original file line number Diff line number Diff line change
Expand Up @@ -65,6 +65,56 @@ export interface UserConfig {
"default-setup"?: DefaultSetupConfig;
}

/**
* Merges supported properties from two configuration files. This is intended only for
* use with merging the `config` input provided by Default Setup with a potentially
* richer configuration file provided by a user.
*
* @param logger The logger to use.
* @param fromConfigInput The configuration from Default Setup.
* @param fromConfigFile The user-supplied configuration.
* @returns The combination of both configuration files.
*/
export function mergeUserConfigs(
Comment thread
mbg marked this conversation as resolved.
Outdated
logger: Logger,
fromConfigInput: UserConfig,
fromConfigFile: UserConfig,
): UserConfig {
logger.debug(
"Combining configuration files from 'config' and 'config-file' inputs",
);

// Combine all specified threat models from both sources.
const threatModels = new Set(fromConfigInput["threat-models"] || []);
for (const configFileThreatModel of fromConfigFile["threat-models"] || []) {
threatModels.add(configFileThreatModel);
}

// Warn if there is a 'default-setup' configuration key in the user-supplied configuration,
// since it is not meant to be used and we therefore ignore it here.
if (fromConfigFile["default-setup"]) {
logger.warning(
`The 'default-setup' configuration key is not supported in user-supplied configuration files and will be ignored.`,
);
}

// Since we expect the `fromConfigInput` configuration to be provided by Default Setup,
// we expect a limited set of options. Therefore, we base the overall configuration on
// the one provided via the `config-file` input, which may be richer.
const result = { ...fromConfigFile };
delete result["threat-models"];
delete result["default-setup"];

if (fromConfigInput["default-setup"]) {
result["default-setup"] = fromConfigInput["default-setup"];
}
if (threatModels.size > 0) {
result["threat-models"] = Array.from(threatModels);
}

return result;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It is probably worth logging a warning that is sent to telemetry if we find any other properties in fromConfigInput. If we format this as a telemetry diagnostic, we can set the internal-error tag on the reporting descriptor to send exceptions to Sentry.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I have added diagnostics for unrecognised and invalid keys in 7c961fa and f630f8f

}

/**
* Represents additional configuration data from a source other than
* a configuration file.
Expand Down