Reusable Helm chart version bump guard for Woodpecker and local policy hooks.
  • Go 96.7%
  • Shell 2%
  • Dockerfile 1.3%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Yael 0c28dcb9db
All checks were successful
ci/woodpecker/push/test Pipeline was successful
Create gated release tag / release (push) Successful in 1m8s
ci/woodpecker/tag/release Pipeline was successful
Merge pull request 'chore(deps): update woodpeckerci/plugin-docker-buildx docker tag to v6.1.2' (#39) from renovate/woodpeckerci-plugin-docker-buildx-6.x into main
2026-09-25 00:34:13 +00:00
.forgejo/workflows ci: gate releases and enable persistent caching 2026-08-11 03:01:04 +02:00
.woodpecker chore(deps): update woodpeckerci/plugin-docker-buildx docker tag to v6.1.2 2026-09-24 23:35:29 +00:00
cmd/chart-version-guard feat: add Helm chart version guard 2026-05-31 14:11:34 +02:00
hack ci: gate releases and enable persistent caching 2026-08-11 03:01:04 +02:00
internal feat: add --ignore to skip chart roots 2026-09-18 18:48:25 +02:00
.dockerignore feat: add Helm chart version guard 2026-05-31 14:11:34 +02:00
.gitignore feat: add Helm chart version guard 2026-05-31 14:11:34 +02:00
.pre-commit-hooks.yaml feat: add Helm chart version guard 2026-05-31 14:11:34 +02:00
Dockerfile chore(deps): update weekly container digest refresh 2026-09-19 22:19:07 +00:00
go.mod chore(deps): update module go.yaml.in/yaml/v3 to v3.0.5 2026-07-26 19:30:47 +00:00
go.sum chore(deps): update module go.yaml.in/yaml/v3 to v3.0.5 2026-07-26 19:30:47 +00:00
README.md feat: add --ignore to skip chart roots 2026-09-18 18:48:25 +02:00
renovate.json Add renovate.json 2026-05-31 15:20:39 +00:00
VERSION ci: gate releases and enable persistent caching 2026-08-11 03:01:04 +02:00

chart-version-guard

chart-version-guard enforces the GitOps rule that Helm chart behavior changes must bump the chart version.

It watches chart-local templates/, values.yaml, values.yml, values-*.yaml, and values-*.yml files. If any of those files change, the same chart's top-level Chart.yaml version must change between the base and head refs.

Usage

Check a local branch:

chart-version-guard check --base origin/main --head HEAD --repo .

Check from Woodpecker:

chart-version-guard check --ci woodpecker --repo .

Patch-bump missing chart versions locally:

chart-version-guard bump --base origin/main --head HEAD --repo . --write

Patch-bump missing chart versions from Woodpecker:

chart-version-guard bump --ci woodpecker --repo . --write

Skip chart roots that the repository does not release, such as upstream copies in a fork (repeatable; path.Match globs, and a trailing /** matches the whole subtree):

chart-version-guard check --ci woodpecker --repo . --ignore 'charts/**'

Rules

  • Chart roots are discovered by Chart.yaml.
  • Vendored dependency charts under a chart's charts/ directory are ignored.
  • Charts matching an --ignore pattern are skipped, and their files are not attributed to a parent chart.
  • Dependency version changes inside Chart.yaml do not satisfy or require a chart version bump.
  • New charts pass when their new Chart.yaml has a top-level version.
  • Deleted charts pass.
  • bump --write only handles strict x.y.z versions.

CI Image

Woodpecker publishes ghcr.io/isityael/chart-version-guard from this repository's .woodpecker/release.yaml pipeline.

Repository

Forgejo is the source of truth:

  • https://git.m0sh1.cc/m0sh1/chart-version-guard

GitHub is maintained as a public push mirror:

  • https://github.com/isityael/chart-version-guard