Files
wickra/repo-metadata.toml
T
kingchenc f7b91f6fa5 chore: use support@wickra.org for contact/author email; drop dead sponsor link (#97)
Now that the wickra.org catch-all mailbox exists, move the project contact +
package-author email off the personal gmail to support@wickra.org across all
surfaces: CODE_OF_CONDUCT, SECURITY, CITATION.cff, Cargo.toml, the npm + PyPI
author fields, the release.yml npm author, and repo-metadata.toml. (The
package-author changes take effect on the next published release.)

repo-metadata.toml's [audit].forbidden still pins kingchencp@gmail.com (the
private commit email) as a banned substring — unchanged.

Also remove the FUNDING.yml custom "https://wickra.org/sponsor" entry: that
page 404s, so the Sponsor button linked to a dead URL. The GitHub Sponsors
entry (github: [kingchenc]) stays.
2026-05-31 23:22:57 +02:00

55 lines
1.9 KiB
TOML

# Single source of truth for repo-level identity (org slug, maintainer email,
# canonical URLs). The audit workflow `.github/workflows/sync-metadata.yml`
# parses this file and fails CI if any tracked file disagrees.
#
# Do NOT edit downstream files by hand for these fields. Edit here, then run
# the workflow locally to spot drift, fix the downstream files until the
# audit is green.
[repo]
org = "wickra-lib"
name = "wickra"
url = "https://github.com/wickra-lib/wickra"
docs_url = "https://docs.wickra.org"
docs_git = "https://github.com/wickra-lib/wickra-docs"
issues_url = "https://github.com/wickra-lib/wickra/issues"
discussions = "https://github.com/wickra-lib/wickra/discussions"
security_url = "https://github.com/wickra-lib/wickra/security/advisories/new"
[maintainer]
# `handle` is the natural-person credit shown in package manifests; it does
# not move with the GitHub org transfer. `github` is the org @-mention slug
# used in CODEOWNERS and prose.
handle = "kingchenc"
email = "support@wickra.org"
github = "wickra-lib"
[badges]
codecov_repo = "wickra-lib/wickra"
ci_workflow = "ci.yml"
[audit]
# Forbidden substrings that must not appear anywhere in the repo outside the
# allowlist below. These are the pre-migration values; if any one of them
# resurfaces in source, the audit workflow fails.
forbidden = [
"kingchenc/wickra",
"kingchencp@gmail.com",
]
# Paths that are exempt from the forbidden-substring scan. Historical
# CHANGELOG sections keep their prose unchanged; auto-generated and ignored
# folders never reach the repo but are listed for parity with `.git/info/exclude`.
allowlist = [
"target/",
"node_modules/",
"fuzz/target/",
".venv/",
"Cargo.lock",
"package-lock.json",
"bindings/node/index.js",
"bindings/node/index.d.ts",
"repo-metadata.toml",
".github/scripts/sync-metadata.py",
]