Enforce the project policy in CI
Run a full-project attribution check in pull requests and inspect the resulting findings.
Start with a local passing policy
Run Doctor locally, fix the supported paths, and commit bao.config.json. Use your own registered Builder Code in the workflow. Keep attribution checks alongside your existing tests.
pnpm exec bao doctor --profile strictAdd the released attribution Action
Save this workflow as .github/workflows/validate-attribution.yml. It checks the full project rather than only changed files. v0.5.0 is the repository’s documented released Action reference; B20 is a separate unreleased candidate workflow.
name: Validate Attribution
on:
pull_request:
permissions:
contents: read
jobs:
attribution:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6
with:
fetch-depth: 0
- uses: horn111/base-attribution-os/packages/github-action@v0.5.0
with:
builder-code: bc_abc123
profile: strict
changed-only: "false"
fail-on-missing: "true"Review paths, not just a percentage
The Action produces annotations, a job summary, outputs, and optional SARIF. Inspect missing, wrong-code, and unresolved findings. Changed-only checks and baselines are available, but their scope must remain explicit when making a merge decision.