Revert to branch-scoped self-publishing CI/CD - #204

Merged
ptr727 merged 9 commits into
developfrom
feature/branch-scoped-cicd
Jun 28, 2026
Merged

Revert to branch-scoped self-publishing CI/CD#204
ptr727 merged 9 commits into
developfrom
feature/branch-scoped-cicd

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Summary

Replaces the shared project-template CI/CD with a branch-scoped, self-sufficient workflow set written for this repo. One run targets the branch it was triggered on; NBGV versions it natively; a reusable validate-task (unit tests + lint) gates both the pull request and the publisher; and a shipped-input push to main/develop self-publishes (main stable, develop prerelease) with no schedule or PUBLISH_ON_MERGE.

Changes

  • WORKFLOW.md - canonical branch-scoped CI/CD spec + audit methodology (5A static / 5B trace / 5C live / 5D config).
  • validate-task.yml - unit-test + lint (csharpier, dotnet format, markdownlint, cspell, actionlint); the PR gate and the publish job both need: it, so nothing publishes that would fail the PR.
  • Rewrote publish-release / test-pull-request / build-release-task; deleted get-version / build-nugetlibrary / build-datebadge.
  • NuGet publishing is keyless via OIDC trusted publishing (NUGET_USERNAME, no API key).
  • repo-config/ - rulesets, settings, and configure.sh apply|check (the 5D config audit).
  • cspell.json - single-source spell dictionary (extension + CLI + CI read it).
  • Reconciled AGENTS.md / CODESTYLE.md / README.md / HISTORY.md; bumped to 1.5.

Go-live coordination (maintainer)

  • The aggregator required check is renamed to Check pull request workflow status job. The live ruleset still requires the old name, so repo-config/configure.sh apply must run in lockstep with merging this PR (it also fixes delete_branch_on_merge). Until then the live required check is satisfied by the base-resolved old workflow.
  • version.json is bumped (1.4 -> 1.5), a shipped input, so merging this to develop will auto-publish a 1.5 prerelease to NuGet. Intended, but flagging it.

🤖 Generated with Claude Code

Replace the shared project-template workflow model with a branch-scoped,
self-sufficient set written for this repo. One run targets the branch it was
triggered on; NBGV versions it natively (no IGNORE_GITHUB_REF / checkout -B);
a reusable validate-task (unit tests + lint) gates both the pull request and
the publisher; and a shipped-input push to main/develop self-publishes (main
stable, develop prerelease) with no schedule or PUBLISH_ON_MERGE.
- Add WORKFLOW.md: canonical branch-scoped CI/CD spec plus audit methodology.
- Add validate-task.yml (unit-test plus lint: csharpier, dotnet format,
markdownlint, cspell, actionlint); PR gate and publish job both need it.
- Rewrite publish-release/test-pull-request/build-release-task; delete the
get-version/build-nugetlibrary/build-datebadge tasks.
- NuGet publishing is keyless via OIDC trusted publishing (NUGET_USERNAME, no
long-lived API key).
- Add repo-config/ (rulesets, settings, configure.sh apply|check 5D audit) and
cspell.json (single-source spell dictionary).
- Reconcile AGENTS.md/CODESTYLE.md/README.md/HISTORY.md; bump version to 1.5.
Rename the required status check to "Check pull request workflow status job";
the live ruleset must be applied in lockstep (repo-config/configure.sh apply).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 27, 2026 21:21

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR replaces the template-derived, matrix/scheduled CI/CD with a repo-specific, branch-scoped workflow set where each run targets only the triggering branch (main = stable, develop = prerelease), reusing a single validate-task gate for both PR validation and publishing. It also codifies repo settings/rulesets/secrets-as-names under repo-config/ and updates docs/versioning to reflect the new operational contract.

Changes:

  • Added a canonical CI/CD contract + audit methodology (WORKFLOW.md) and a config-as-code audit/apply toolchain (repo-config/).
  • Introduced validate-task.yml (unit test + lint suite) and rewired test-pull-request.yml / publish-release.yml / build-release-task.yml around branch-scoped self-publishing + OIDC NuGet trusted publishing.
  • Updated release/docs metadata (bump version.json to 1.5; refreshed README.md, HISTORY.md, AGENTS.md, CODESTYLE.md; centralized spelling words in cspell.json and removed workspace-local dictionary).

Reviewed changes

Copilot reviewed 23 out of 23 changed files in this pull request and generated 5 comments.

Show a summary per file
FileDescription
WORKFLOW.mdNew end-to-end CI/CD contract (architecture, guarantees, and audit methodology).
version.jsonBumps version floor from 1.4 to 1.5.
repo-config/settings.jsonDeclares desired repository settings (auto-merge, merge methods, delete-branch-on-merge).
repo-config/ruleset-main.jsonCodifies main ruleset (merge-commit only, required check, signatures, strict off).
repo-config/ruleset-develop.jsonCodifies develop ruleset (squash-only + linear history, required check, signatures, strict off).
repo-config/README.mdDocuments config-as-code scope and the required-check rename lockstep.
repo-config/configure.shAdds `apply
README.mdUpdates release notes, CI/CD description, required-check name, and publishing/auth model.
HISTORY.mdAdds 1.5 entry describing CI/CD revert/rework and keyless publishing.
LanguageTags.code-workspaceRemoves embedded cSpell word list (now centralized in cspell.json).
cspell.jsonNew single-source spell dictionary + ignore paths.
CODESTYLE.mdUpdates clean-compile/lint/spell guidance to match CI + cspell.json.
AGENTS.mdRe-points CI/CD canon to WORKFLOW.md and updates merge/release semantics accordingly.
.github/workflows/validate-task.ymlNew reusable validation gate (unit tests + CSharpier/dotnet-format/markdownlint/cspell/actionlint).
.github/workflows/test-pull-request.ymlReworked CI entry workflow to run on push + produce the ruleset-bound aggregator check.
.github/workflows/publish-release.ymlReworked publisher to be branch-scoped + shipped-input path gated; uses validate-task gate.
.github/workflows/build-release-task.ymlReworked build/version/publish/release reusable task; adds OIDC NuGet trusted publishing and simplified asset handling.
.github/workflows/run-periodic-codegen-pull-request.ymlUpdates description/comments; maintains scheduled daily codegen entry workflow.
.github/workflows/run-codegen-pull-request-task.ymlUpdates documentation/comments around per-branch codegen PR creation.
.github/workflows/merge-bot-pull-request.ymlRemoves semver-major NuGet exception; makes Dependabot auto-merge unconditional on green checks.
.github/workflows/get-version-task.ymlDeleted (versioning now handled inside build-release-task.yml).
.github/workflows/build-nugetlibrary-task.ymlDeleted (logic folded into build-release-task.yml).
.github/workflows/build-datebadge-task.ymlDeleted (BYOB date badge removed).

Comment threadWORKFLOW.md Outdated
Comment threadWORKFLOW.md Outdated
Comment thread.github/workflows/build-release-task.yml Outdated
Comment thread.github/workflows/validate-task.yml Outdated
Comment thread.github/workflows/test-pull-request.yml Outdated
ptr727and others added 2 commits June 27, 2026 14:26
The project sets GeneratePackageOnBuild, so the build emits the .nupkg
(+ .snupkg). Running dotnet pack on top of that double-packs and fails to
find the assembly under the .artifacts layout ("LanguageTags.dll to be
packed was not found"). Build instead, redirecting OutputPath and
PackageOutputPath out of .artifacts, matching the prior working task.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…ctionlint
- WORKFLOW.md: frame dependency-bump exclusion as a deliberate churn-avoidance
policy, not a "no compiled code change" technical invariant (x2).
- build-release-task: correct the smoke validate-release skip rationale; smoke
can run on main, so the reason is "smoke never publishes", not "never main".
- validate-task: verify the actionlint release tarball against its published
SHA-256 before extracting/executing it, closing the unchecked-download path.
- test-pull-request: make the no-pull_request-trigger fork constraint and the
maintainer workflow explicit in the header.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 27, 2026 21:31

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 23 out of 23 changed files in this pull request and generated 2 comments.

Comment thread.github/workflows/build-release-task.yml
Comment threadREADME.md Outdated
ptr727and others added 2 commits June 27, 2026 14:39
… action
- Replace Unicode arrows (->) and an ellipsis (...) in README.md and the
dependabot.yml comments with ASCII, per AGENTS.md "no Unicode arrows / no
ellipsis character".
- Lint workflows via the SHA-pinned raven-actions/actionlint action (vendors
actionlint + shellcheck) instead of a hand-rolled curl download, matching
the repo's pin-every-action convention and dropping manual checksum upkeep.
The snupkg comment is a false positive: dotnet nuget push auto-pushes the
co-located .snupkg to nuget.org (no --no-symbols), as the workflow documents.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Comments:
- Trim verbose workflow comments to the non-obvious points. Move the snupkg
note onto the push step, name GitCommitId where comments said "built
commit", and make the artifact-delete gate explicit.
- Restructure publish-release's top comment into bullets, and drop prose
semicolons and inline spec-section refs (D4.6 etc.) across the workflows.
- Reflow dependabot.yml comments to ~120-column structured lines.
- AGENTS.md comments rule now prefers structure over a long prose paragraph.
Scope docs to C# and Actions, dropping shared-template carryover:
- Remove the Python section and the multi-language / derived-repo framing
from CODESTYLE.md; de-template .editorconfig, copilot-instructions.md, and
.vscode/tasks.json.
- Prune orphaned Python-tooling words from cspell.json.
tasks.json: add "Run Codegen" and "Codegen and Format" (codegen then
CSharpier, since generated line lengths are not always CSharpier-aligned).
README contributing/setup now point to WORKFLOW.md, CODESTYLE.md, and
repo-config (maintainer edit).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 27, 2026 22:57

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 27 out of 27 changed files in this pull request and generated 2 comments.

Comment threadWORKFLOW.md Outdated
Comment threadcspell.json Outdated
- Reconcile the Dependabot/fork validation contract: there is no pull_request
trigger, so Dependabot PRs (in-repo branches) validate via their push, and
only forks (which cannot push) need maintainer action. Previously the doc
claimed a base-resolved pull_request fallback that does not exist.
- cspell: set language to en-US to match the documented US-English rule.
- Remove the temporary go-live adoption note.
- Drop the project-type generality section and the multi-shape / portability
framing, scoping the spec to this NuGet library's workflows.
- Fix a broken concurrency sentence and clause-joining semicolons.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 27 out of 27 changed files in this pull request and generated 2 comments.

Comment thread.github/workflows/build-release-task.yml
Comment threadrepo-config/configure.sh
ptr727and others added 2 commits June 27, 2026 16:19
check_secrets now passes --paginate to the actions/secrets and
dependabot/secrets endpoints, so a repo with more than 30 secrets cannot miss
a required name and report a false failure.
The NuGet/login output finding is a false positive: the pinned
NuGet/login@v1.2.0 action.yml outputs NUGET_API_KEY, which the push step uses.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Tighten the verbose narrative in sections 0 and 3 and the longest guarantees
(D4.6, D8.3), drop redundant re-explanation, and remove clause-joining
semicolons. All guarantees (D0-D10) and scenarios (S1-S15) are preserved.
Also fix a model-paragraph inconsistency: it listed a runtime-dependency
update as auto-publishing, but dependency bumps are excluded from the
shipped-input inclusion list. The package publishes on a shipped-input change.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 27, 2026 23:28

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 27 out of 27 changed files in this pull request and generated 4 comments.

Comment thread.github/workflows/test-pull-request.yml
Comment threadrepo-config/configure.sh Outdated
Comment threadrepo-config/README.md
Comment threadrepo-config/README.md Outdated
- test-pull-request: restrict the push trigger to branches ['**'] so release
tags never re-run CI (the contract is CI for every branch, not tags).
- configure.sh and repo-config README: both check and apply use admin-only
rulesets/secrets endpoints, so check needs an admin-authenticated gh token
too (read-only, but not the default CI token). Corrected the misleading
"safe for CI" wording.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@ptr727
ptr727 merged commit b945a2b into developJun 28, 2026
10 checks passed
@ptr727
ptr727 deleted the feature/branch-scoped-cicd branch June 28, 2026 00:18
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Revert to branch-scoped self-publishing CI/CD - #204

Merged
ptr727 merged 9 commits into
developfrom
feature/branch-scoped-cicd
Jun 28, 2026
Merged

Revert to branch-scoped self-publishing CI/CD#204
ptr727 merged 9 commits into
developfrom
feature/branch-scoped-cicd

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Summary

Replaces the shared project-template CI/CD with a branch-scoped, self-sufficient workflow set written for this repo. One run targets the branch it was triggered on; NBGV versions it natively; a reusable validate-task (unit tests + lint) gates both the pull request and the publisher; and a shipped-input push to main/develop self-publishes (main stable, develop prerelease) with no schedule or PUBLISH_ON_MERGE.

Changes

  • WORKFLOW.md - canonical branch-scoped CI/CD spec + audit methodology (5A static / 5B trace / 5C live / 5D config).
  • validate-task.yml - unit-test + lint (csharpier, dotnet format, markdownlint, cspell, actionlint); the PR gate and the publish job both need: it, so nothing publishes that would fail the PR.
  • Rewrote publish-release / test-pull-request / build-release-task; deleted get-version / build-nugetlibrary / build-datebadge.
  • NuGet publishing is keyless via OIDC trusted publishing (NUGET_USERNAME, no API key).
  • repo-config/ - rulesets, settings, and configure.sh apply|check (the 5D config audit).
  • cspell.json - single-source spell dictionary (extension + CLI + CI read it).
  • Reconciled AGENTS.md / CODESTYLE.md / README.md / HISTORY.md; bumped to 1.5.

Go-live coordination (maintainer)

  • The aggregator required check is renamed to Check pull request workflow status job. The live ruleset still requires the old name, so repo-config/configure.sh apply must run in lockstep with merging this PR (it also fixes delete_branch_on_merge). Until then the live required check is satisfied by the base-resolved old workflow.
  • version.json is bumped (1.4 -> 1.5), a shipped input, so merging this to develop will auto-publish a 1.5 prerelease to NuGet. Intended, but flagging it.

🤖 Generated with Claude Code

Replace the shared project-template workflow model with a branch-scoped,
self-sufficient set written for this repo. One run targets the branch it was
triggered on; NBGV versions it natively (no IGNORE_GITHUB_REF / checkout -B);
a reusable validate-task (unit tests + lint) gates both the pull request and
the publisher; and a shipped-input push to main/develop self-publishes (main
stable, develop prerelease) with no schedule or PUBLISH_ON_MERGE.
- Add WORKFLOW.md: canonical branch-scoped CI/CD spec plus audit methodology.
- Add validate-task.yml (unit-test plus lint: csharpier, dotnet format,
markdownlint, cspell, actionlint); PR gate and publish job both need it.
- Rewrite publish-release/test-pull-request/build-release-task; delete the
get-version/build-nugetlibrary/build-datebadge tasks.
- NuGet publishing is keyless via OIDC trusted publishing (NUGET_USERNAME, no
long-lived API key).
- Add repo-config/ (rulesets, settings, configure.sh apply|check 5D audit) and
cspell.json (single-source spell dictionary).
- Reconcile AGENTS.md/CODESTYLE.md/README.md/HISTORY.md; bump version to 1.5.
Rename the required status check to "Check pull request workflow status job";
the live ruleset must be applied in lockstep (repo-config/configure.sh apply).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 27, 2026 21:21

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR replaces the template-derived, matrix/scheduled CI/CD with a repo-specific, branch-scoped workflow set where each run targets only the triggering branch (main = stable, develop = prerelease), reusing a single validate-task gate for both PR validation and publishing. It also codifies repo settings/rulesets/secrets-as-names under repo-config/ and updates docs/versioning to reflect the new operational contract.

Changes:

  • Added a canonical CI/CD contract + audit methodology (WORKFLOW.md) and a config-as-code audit/apply toolchain (repo-config/).
  • Introduced validate-task.yml (unit test + lint suite) and rewired test-pull-request.yml / publish-release.yml / build-release-task.yml around branch-scoped self-publishing + OIDC NuGet trusted publishing.
  • Updated release/docs metadata (bump version.json to 1.5; refreshed README.md, HISTORY.md, AGENTS.md, CODESTYLE.md; centralized spelling words in cspell.json and removed workspace-local dictionary).

Reviewed changes

Copilot reviewed 23 out of 23 changed files in this pull request and generated 5 comments.

Show a summary per file
FileDescription
WORKFLOW.mdNew end-to-end CI/CD contract (architecture, guarantees, and audit methodology).
version.jsonBumps version floor from 1.4 to 1.5.
repo-config/settings.jsonDeclares desired repository settings (auto-merge, merge methods, delete-branch-on-merge).
repo-config/ruleset-main.jsonCodifies main ruleset (merge-commit only, required check, signatures, strict off).
repo-config/ruleset-develop.jsonCodifies develop ruleset (squash-only + linear history, required check, signatures, strict off).
repo-config/README.mdDocuments config-as-code scope and the required-check rename lockstep.
repo-config/configure.shAdds `apply
README.mdUpdates release notes, CI/CD description, required-check name, and publishing/auth model.
HISTORY.mdAdds 1.5 entry describing CI/CD revert/rework and keyless publishing.
LanguageTags.code-workspaceRemoves embedded cSpell word list (now centralized in cspell.json).
cspell.jsonNew single-source spell dictionary + ignore paths.
CODESTYLE.mdUpdates clean-compile/lint/spell guidance to match CI + cspell.json.
AGENTS.mdRe-points CI/CD canon to WORKFLOW.md and updates merge/release semantics accordingly.
.github/workflows/validate-task.ymlNew reusable validation gate (unit tests + CSharpier/dotnet-format/markdownlint/cspell/actionlint).
.github/workflows/test-pull-request.ymlReworked CI entry workflow to run on push + produce the ruleset-bound aggregator check.
.github/workflows/publish-release.ymlReworked publisher to be branch-scoped + shipped-input path gated; uses validate-task gate.
.github/workflows/build-release-task.ymlReworked build/version/publish/release reusable task; adds OIDC NuGet trusted publishing and simplified asset handling.
.github/workflows/run-periodic-codegen-pull-request.ymlUpdates description/comments; maintains scheduled daily codegen entry workflow.
.github/workflows/run-codegen-pull-request-task.ymlUpdates documentation/comments around per-branch codegen PR creation.
.github/workflows/merge-bot-pull-request.ymlRemoves semver-major NuGet exception; makes Dependabot auto-merge unconditional on green checks.
.github/workflows/get-version-task.ymlDeleted (versioning now handled inside build-release-task.yml).
.github/workflows/build-nugetlibrary-task.ymlDeleted (logic folded into build-release-task.yml).
.github/workflows/build-datebadge-task.ymlDeleted (BYOB date badge removed).

Comment threadWORKFLOW.md Outdated
Comment threadWORKFLOW.md Outdated
Comment thread.github/workflows/build-release-task.yml Outdated
Comment thread.github/workflows/validate-task.yml Outdated
Comment thread.github/workflows/test-pull-request.yml Outdated
ptr727and others added 2 commits June 27, 2026 14:26
The project sets GeneratePackageOnBuild, so the build emits the .nupkg
(+ .snupkg). Running dotnet pack on top of that double-packs and fails to
find the assembly under the .artifacts layout ("LanguageTags.dll to be
packed was not found"). Build instead, redirecting OutputPath and
PackageOutputPath out of .artifacts, matching the prior working task.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…ctionlint
- WORKFLOW.md: frame dependency-bump exclusion as a deliberate churn-avoidance
policy, not a "no compiled code change" technical invariant (x2).
- build-release-task: correct the smoke validate-release skip rationale; smoke
can run on main, so the reason is "smoke never publishes", not "never main".
- validate-task: verify the actionlint release tarball against its published
SHA-256 before extracting/executing it, closing the unchecked-download path.
- test-pull-request: make the no-pull_request-trigger fork constraint and the
maintainer workflow explicit in the header.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 27, 2026 21:31

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 23 out of 23 changed files in this pull request and generated 2 comments.

Comment thread.github/workflows/build-release-task.yml
Comment threadREADME.md Outdated
ptr727and others added 2 commits June 27, 2026 14:39
… action
- Replace Unicode arrows (->) and an ellipsis (...) in README.md and the
dependabot.yml comments with ASCII, per AGENTS.md "no Unicode arrows / no
ellipsis character".
- Lint workflows via the SHA-pinned raven-actions/actionlint action (vendors
actionlint + shellcheck) instead of a hand-rolled curl download, matching
the repo's pin-every-action convention and dropping manual checksum upkeep.
The snupkg comment is a false positive: dotnet nuget push auto-pushes the
co-located .snupkg to nuget.org (no --no-symbols), as the workflow documents.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Comments:
- Trim verbose workflow comments to the non-obvious points. Move the snupkg
note onto the push step, name GitCommitId where comments said "built
commit", and make the artifact-delete gate explicit.
- Restructure publish-release's top comment into bullets, and drop prose
semicolons and inline spec-section refs (D4.6 etc.) across the workflows.
- Reflow dependabot.yml comments to ~120-column structured lines.
- AGENTS.md comments rule now prefers structure over a long prose paragraph.
Scope docs to C# and Actions, dropping shared-template carryover:
- Remove the Python section and the multi-language / derived-repo framing
from CODESTYLE.md; de-template .editorconfig, copilot-instructions.md, and
.vscode/tasks.json.
- Prune orphaned Python-tooling words from cspell.json.
tasks.json: add "Run Codegen" and "Codegen and Format" (codegen then
CSharpier, since generated line lengths are not always CSharpier-aligned).
README contributing/setup now point to WORKFLOW.md, CODESTYLE.md, and
repo-config (maintainer edit).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 27, 2026 22:57

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 27 out of 27 changed files in this pull request and generated 2 comments.

Comment threadWORKFLOW.md Outdated
Comment threadcspell.json Outdated
- Reconcile the Dependabot/fork validation contract: there is no pull_request
trigger, so Dependabot PRs (in-repo branches) validate via their push, and
only forks (which cannot push) need maintainer action. Previously the doc
claimed a base-resolved pull_request fallback that does not exist.
- cspell: set language to en-US to match the documented US-English rule.
- Remove the temporary go-live adoption note.
- Drop the project-type generality section and the multi-shape / portability
framing, scoping the spec to this NuGet library's workflows.
- Fix a broken concurrency sentence and clause-joining semicolons.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 27 out of 27 changed files in this pull request and generated 2 comments.

Comment thread.github/workflows/build-release-task.yml
Comment threadrepo-config/configure.sh
ptr727and others added 2 commits June 27, 2026 16:19
check_secrets now passes --paginate to the actions/secrets and
dependabot/secrets endpoints, so a repo with more than 30 secrets cannot miss
a required name and report a false failure.
The NuGet/login output finding is a false positive: the pinned
NuGet/login@v1.2.0 action.yml outputs NUGET_API_KEY, which the push step uses.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Tighten the verbose narrative in sections 0 and 3 and the longest guarantees
(D4.6, D8.3), drop redundant re-explanation, and remove clause-joining
semicolons. All guarantees (D0-D10) and scenarios (S1-S15) are preserved.
Also fix a model-paragraph inconsistency: it listed a runtime-dependency
update as auto-publishing, but dependency bumps are excluded from the
shipped-input inclusion list. The package publishes on a shipped-input change.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 27, 2026 23:28

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 27 out of 27 changed files in this pull request and generated 4 comments.

Comment thread.github/workflows/test-pull-request.yml
Comment threadrepo-config/configure.sh Outdated
Comment threadrepo-config/README.md
Comment threadrepo-config/README.md Outdated
- test-pull-request: restrict the push trigger to branches ['**'] so release
tags never re-run CI (the contract is CI for every branch, not tags).
- configure.sh and repo-config README: both check and apply use admin-only
rulesets/secrets endpoints, so check needs an admin-authenticated gh token
too (read-only, but not the default CI token). Corrected the misleading
"safe for CI" wording.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@ptr727
ptr727 merged commit b945a2b into developJun 28, 2026
10 checks passed
@ptr727
ptr727 deleted the feature/branch-scoped-cicd branch June 28, 2026 00:18
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Revert to branch-scoped self-publishing CI/CD - #204

Merged
ptr727 merged 9 commits into
developfrom
feature/branch-scoped-cicd
Jun 28, 2026
Merged

Revert to branch-scoped self-publishing CI/CD#204
ptr727 merged 9 commits into
developfrom
feature/branch-scoped-cicd

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Summary

Replaces the shared project-template CI/CD with a branch-scoped, self-sufficient workflow set written for this repo. One run targets the branch it was triggered on; NBGV versions it natively; a reusable validate-task (unit tests + lint) gates both the pull request and the publisher; and a shipped-input push to main/develop self-publishes (main stable, develop prerelease) with no schedule or PUBLISH_ON_MERGE.

Changes

  • WORKFLOW.md - canonical branch-scoped CI/CD spec + audit methodology (5A static / 5B trace / 5C live / 5D config).
  • validate-task.yml - unit-test + lint (csharpier, dotnet format, markdownlint, cspell, actionlint); the PR gate and the publish job both need: it, so nothing publishes that would fail the PR.
  • Rewrote publish-release / test-pull-request / build-release-task; deleted get-version / build-nugetlibrary / build-datebadge.
  • NuGet publishing is keyless via OIDC trusted publishing (NUGET_USERNAME, no API key).
  • repo-config/ - rulesets, settings, and configure.sh apply|check (the 5D config audit).
  • cspell.json - single-source spell dictionary (extension + CLI + CI read it).
  • Reconciled AGENTS.md / CODESTYLE.md / README.md / HISTORY.md; bumped to 1.5.

Go-live coordination (maintainer)

  • The aggregator required check is renamed to Check pull request workflow status job. The live ruleset still requires the old name, so repo-config/configure.sh apply must run in lockstep with merging this PR (it also fixes delete_branch_on_merge). Until then the live required check is satisfied by the base-resolved old workflow.
  • version.json is bumped (1.4 -> 1.5), a shipped input, so merging this to develop will auto-publish a 1.5 prerelease to NuGet. Intended, but flagging it.

🤖 Generated with Claude Code

Replace the shared project-template workflow model with a branch-scoped,
self-sufficient set written for this repo. One run targets the branch it was
triggered on; NBGV versions it natively (no IGNORE_GITHUB_REF / checkout -B);
a reusable validate-task (unit tests + lint) gates both the pull request and
the publisher; and a shipped-input push to main/develop self-publishes (main
stable, develop prerelease) with no schedule or PUBLISH_ON_MERGE.
- Add WORKFLOW.md: canonical branch-scoped CI/CD spec plus audit methodology.
- Add validate-task.yml (unit-test plus lint: csharpier, dotnet format,
markdownlint, cspell, actionlint); PR gate and publish job both need it.
- Rewrite publish-release/test-pull-request/build-release-task; delete the
get-version/build-nugetlibrary/build-datebadge tasks.
- NuGet publishing is keyless via OIDC trusted publishing (NUGET_USERNAME, no
long-lived API key).
- Add repo-config/ (rulesets, settings, configure.sh apply|check 5D audit) and
cspell.json (single-source spell dictionary).
- Reconcile AGENTS.md/CODESTYLE.md/README.md/HISTORY.md; bump version to 1.5.
Rename the required status check to "Check pull request workflow status job";
the live ruleset must be applied in lockstep (repo-config/configure.sh apply).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 27, 2026 21:21

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR replaces the template-derived, matrix/scheduled CI/CD with a repo-specific, branch-scoped workflow set where each run targets only the triggering branch (main = stable, develop = prerelease), reusing a single validate-task gate for both PR validation and publishing. It also codifies repo settings/rulesets/secrets-as-names under repo-config/ and updates docs/versioning to reflect the new operational contract.

Changes:

  • Added a canonical CI/CD contract + audit methodology (WORKFLOW.md) and a config-as-code audit/apply toolchain (repo-config/).
  • Introduced validate-task.yml (unit test + lint suite) and rewired test-pull-request.yml / publish-release.yml / build-release-task.yml around branch-scoped self-publishing + OIDC NuGet trusted publishing.
  • Updated release/docs metadata (bump version.json to 1.5; refreshed README.md, HISTORY.md, AGENTS.md, CODESTYLE.md; centralized spelling words in cspell.json and removed workspace-local dictionary).

Reviewed changes

Copilot reviewed 23 out of 23 changed files in this pull request and generated 5 comments.

Show a summary per file
FileDescription
WORKFLOW.mdNew end-to-end CI/CD contract (architecture, guarantees, and audit methodology).
version.jsonBumps version floor from 1.4 to 1.5.
repo-config/settings.jsonDeclares desired repository settings (auto-merge, merge methods, delete-branch-on-merge).
repo-config/ruleset-main.jsonCodifies main ruleset (merge-commit only, required check, signatures, strict off).
repo-config/ruleset-develop.jsonCodifies develop ruleset (squash-only + linear history, required check, signatures, strict off).
repo-config/README.mdDocuments config-as-code scope and the required-check rename lockstep.
repo-config/configure.shAdds `apply
README.mdUpdates release notes, CI/CD description, required-check name, and publishing/auth model.
HISTORY.mdAdds 1.5 entry describing CI/CD revert/rework and keyless publishing.
LanguageTags.code-workspaceRemoves embedded cSpell word list (now centralized in cspell.json).
cspell.jsonNew single-source spell dictionary + ignore paths.
CODESTYLE.mdUpdates clean-compile/lint/spell guidance to match CI + cspell.json.
AGENTS.mdRe-points CI/CD canon to WORKFLOW.md and updates merge/release semantics accordingly.
.github/workflows/validate-task.ymlNew reusable validation gate (unit tests + CSharpier/dotnet-format/markdownlint/cspell/actionlint).
.github/workflows/test-pull-request.ymlReworked CI entry workflow to run on push + produce the ruleset-bound aggregator check.
.github/workflows/publish-release.ymlReworked publisher to be branch-scoped + shipped-input path gated; uses validate-task gate.
.github/workflows/build-release-task.ymlReworked build/version/publish/release reusable task; adds OIDC NuGet trusted publishing and simplified asset handling.
.github/workflows/run-periodic-codegen-pull-request.ymlUpdates description/comments; maintains scheduled daily codegen entry workflow.
.github/workflows/run-codegen-pull-request-task.ymlUpdates documentation/comments around per-branch codegen PR creation.
.github/workflows/merge-bot-pull-request.ymlRemoves semver-major NuGet exception; makes Dependabot auto-merge unconditional on green checks.
.github/workflows/get-version-task.ymlDeleted (versioning now handled inside build-release-task.yml).
.github/workflows/build-nugetlibrary-task.ymlDeleted (logic folded into build-release-task.yml).
.github/workflows/build-datebadge-task.ymlDeleted (BYOB date badge removed).

Comment threadWORKFLOW.md Outdated
Comment threadWORKFLOW.md Outdated
Comment thread.github/workflows/build-release-task.yml Outdated
Comment thread.github/workflows/validate-task.yml Outdated
Comment thread.github/workflows/test-pull-request.yml Outdated
ptr727and others added 2 commits June 27, 2026 14:26
The project sets GeneratePackageOnBuild, so the build emits the .nupkg
(+ .snupkg). Running dotnet pack on top of that double-packs and fails to
find the assembly under the .artifacts layout ("LanguageTags.dll to be
packed was not found"). Build instead, redirecting OutputPath and
PackageOutputPath out of .artifacts, matching the prior working task.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…ctionlint
- WORKFLOW.md: frame dependency-bump exclusion as a deliberate churn-avoidance
policy, not a "no compiled code change" technical invariant (x2).
- build-release-task: correct the smoke validate-release skip rationale; smoke
can run on main, so the reason is "smoke never publishes", not "never main".
- validate-task: verify the actionlint release tarball against its published
SHA-256 before extracting/executing it, closing the unchecked-download path.
- test-pull-request: make the no-pull_request-trigger fork constraint and the
maintainer workflow explicit in the header.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 27, 2026 21:31

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 23 out of 23 changed files in this pull request and generated 2 comments.

Comment thread.github/workflows/build-release-task.yml
Comment threadREADME.md Outdated
ptr727and others added 2 commits June 27, 2026 14:39
… action
- Replace Unicode arrows (->) and an ellipsis (...) in README.md and the
dependabot.yml comments with ASCII, per AGENTS.md "no Unicode arrows / no
ellipsis character".
- Lint workflows via the SHA-pinned raven-actions/actionlint action (vendors
actionlint + shellcheck) instead of a hand-rolled curl download, matching
the repo's pin-every-action convention and dropping manual checksum upkeep.
The snupkg comment is a false positive: dotnet nuget push auto-pushes the
co-located .snupkg to nuget.org (no --no-symbols), as the workflow documents.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Comments:
- Trim verbose workflow comments to the non-obvious points. Move the snupkg
note onto the push step, name GitCommitId where comments said "built
commit", and make the artifact-delete gate explicit.
- Restructure publish-release's top comment into bullets, and drop prose
semicolons and inline spec-section refs (D4.6 etc.) across the workflows.
- Reflow dependabot.yml comments to ~120-column structured lines.
- AGENTS.md comments rule now prefers structure over a long prose paragraph.
Scope docs to C# and Actions, dropping shared-template carryover:
- Remove the Python section and the multi-language / derived-repo framing
from CODESTYLE.md; de-template .editorconfig, copilot-instructions.md, and
.vscode/tasks.json.
- Prune orphaned Python-tooling words from cspell.json.
tasks.json: add "Run Codegen" and "Codegen and Format" (codegen then
CSharpier, since generated line lengths are not always CSharpier-aligned).
README contributing/setup now point to WORKFLOW.md, CODESTYLE.md, and
repo-config (maintainer edit).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 27, 2026 22:57

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 27 out of 27 changed files in this pull request and generated 2 comments.

Comment threadWORKFLOW.md Outdated
Comment threadcspell.json Outdated
- Reconcile the Dependabot/fork validation contract: there is no pull_request
trigger, so Dependabot PRs (in-repo branches) validate via their push, and
only forks (which cannot push) need maintainer action. Previously the doc
claimed a base-resolved pull_request fallback that does not exist.
- cspell: set language to en-US to match the documented US-English rule.
- Remove the temporary go-live adoption note.
- Drop the project-type generality section and the multi-shape / portability
framing, scoping the spec to this NuGet library's workflows.
- Fix a broken concurrency sentence and clause-joining semicolons.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 27 out of 27 changed files in this pull request and generated 2 comments.

Comment thread.github/workflows/build-release-task.yml
Comment threadrepo-config/configure.sh
ptr727and others added 2 commits June 27, 2026 16:19
check_secrets now passes --paginate to the actions/secrets and
dependabot/secrets endpoints, so a repo with more than 30 secrets cannot miss
a required name and report a false failure.
The NuGet/login output finding is a false positive: the pinned
NuGet/login@v1.2.0 action.yml outputs NUGET_API_KEY, which the push step uses.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Tighten the verbose narrative in sections 0 and 3 and the longest guarantees
(D4.6, D8.3), drop redundant re-explanation, and remove clause-joining
semicolons. All guarantees (D0-D10) and scenarios (S1-S15) are preserved.
Also fix a model-paragraph inconsistency: it listed a runtime-dependency
update as auto-publishing, but dependency bumps are excluded from the
shipped-input inclusion list. The package publishes on a shipped-input change.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 27, 2026 23:28

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 27 out of 27 changed files in this pull request and generated 4 comments.

Comment thread.github/workflows/test-pull-request.yml
Comment threadrepo-config/configure.sh Outdated
Comment threadrepo-config/README.md
Comment threadrepo-config/README.md Outdated
- test-pull-request: restrict the push trigger to branches ['**'] so release
tags never re-run CI (the contract is CI for every branch, not tags).
- configure.sh and repo-config README: both check and apply use admin-only
rulesets/secrets endpoints, so check needs an admin-authenticated gh token
too (read-only, but not the default CI token). Corrected the misleading
"safe for CI" wording.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@ptr727
ptr727 merged commit b945a2b into developJun 28, 2026
10 checks passed
@ptr727
ptr727 deleted the feature/branch-scoped-cicd branch June 28, 2026 00:18
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Revert to branch-scoped self-publishing CI/CD - #204

Merged
ptr727 merged 9 commits into
developfrom
feature/branch-scoped-cicd
Jun 28, 2026
Merged

Revert to branch-scoped self-publishing CI/CD#204
ptr727 merged 9 commits into
developfrom
feature/branch-scoped-cicd

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Summary

Replaces the shared project-template CI/CD with a branch-scoped, self-sufficient workflow set written for this repo. One run targets the branch it was triggered on; NBGV versions it natively; a reusable validate-task (unit tests + lint) gates both the pull request and the publisher; and a shipped-input push to main/develop self-publishes (main stable, develop prerelease) with no schedule or PUBLISH_ON_MERGE.

Changes

  • WORKFLOW.md - canonical branch-scoped CI/CD spec + audit methodology (5A static / 5B trace / 5C live / 5D config).
  • validate-task.yml - unit-test + lint (csharpier, dotnet format, markdownlint, cspell, actionlint); the PR gate and the publish job both need: it, so nothing publishes that would fail the PR.
  • Rewrote publish-release / test-pull-request / build-release-task; deleted get-version / build-nugetlibrary / build-datebadge.
  • NuGet publishing is keyless via OIDC trusted publishing (NUGET_USERNAME, no API key).
  • repo-config/ - rulesets, settings, and configure.sh apply|check (the 5D config audit).
  • cspell.json - single-source spell dictionary (extension + CLI + CI read it).
  • Reconciled AGENTS.md / CODESTYLE.md / README.md / HISTORY.md; bumped to 1.5.

Go-live coordination (maintainer)

  • The aggregator required check is renamed to Check pull request workflow status job. The live ruleset still requires the old name, so repo-config/configure.sh apply must run in lockstep with merging this PR (it also fixes delete_branch_on_merge). Until then the live required check is satisfied by the base-resolved old workflow.
  • version.json is bumped (1.4 -> 1.5), a shipped input, so merging this to develop will auto-publish a 1.5 prerelease to NuGet. Intended, but flagging it.

🤖 Generated with Claude Code

Replace the shared project-template workflow model with a branch-scoped,
self-sufficient set written for this repo. One run targets the branch it was
triggered on; NBGV versions it natively (no IGNORE_GITHUB_REF / checkout -B);
a reusable validate-task (unit tests + lint) gates both the pull request and
the publisher; and a shipped-input push to main/develop self-publishes (main
stable, develop prerelease) with no schedule or PUBLISH_ON_MERGE.
- Add WORKFLOW.md: canonical branch-scoped CI/CD spec plus audit methodology.
- Add validate-task.yml (unit-test plus lint: csharpier, dotnet format,
markdownlint, cspell, actionlint); PR gate and publish job both need it.
- Rewrite publish-release/test-pull-request/build-release-task; delete the
get-version/build-nugetlibrary/build-datebadge tasks.
- NuGet publishing is keyless via OIDC trusted publishing (NUGET_USERNAME, no
long-lived API key).
- Add repo-config/ (rulesets, settings, configure.sh apply|check 5D audit) and
cspell.json (single-source spell dictionary).
- Reconcile AGENTS.md/CODESTYLE.md/README.md/HISTORY.md; bump version to 1.5.
Rename the required status check to "Check pull request workflow status job";
the live ruleset must be applied in lockstep (repo-config/configure.sh apply).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 27, 2026 21:21

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR replaces the template-derived, matrix/scheduled CI/CD with a repo-specific, branch-scoped workflow set where each run targets only the triggering branch (main = stable, develop = prerelease), reusing a single validate-task gate for both PR validation and publishing. It also codifies repo settings/rulesets/secrets-as-names under repo-config/ and updates docs/versioning to reflect the new operational contract.

Changes:

  • Added a canonical CI/CD contract + audit methodology (WORKFLOW.md) and a config-as-code audit/apply toolchain (repo-config/).
  • Introduced validate-task.yml (unit test + lint suite) and rewired test-pull-request.yml / publish-release.yml / build-release-task.yml around branch-scoped self-publishing + OIDC NuGet trusted publishing.
  • Updated release/docs metadata (bump version.json to 1.5; refreshed README.md, HISTORY.md, AGENTS.md, CODESTYLE.md; centralized spelling words in cspell.json and removed workspace-local dictionary).

Reviewed changes

Copilot reviewed 23 out of 23 changed files in this pull request and generated 5 comments.

Show a summary per file
FileDescription
WORKFLOW.mdNew end-to-end CI/CD contract (architecture, guarantees, and audit methodology).
version.jsonBumps version floor from 1.4 to 1.5.
repo-config/settings.jsonDeclares desired repository settings (auto-merge, merge methods, delete-branch-on-merge).
repo-config/ruleset-main.jsonCodifies main ruleset (merge-commit only, required check, signatures, strict off).
repo-config/ruleset-develop.jsonCodifies develop ruleset (squash-only + linear history, required check, signatures, strict off).
repo-config/README.mdDocuments config-as-code scope and the required-check rename lockstep.
repo-config/configure.shAdds `apply
README.mdUpdates release notes, CI/CD description, required-check name, and publishing/auth model.
HISTORY.mdAdds 1.5 entry describing CI/CD revert/rework and keyless publishing.
LanguageTags.code-workspaceRemoves embedded cSpell word list (now centralized in cspell.json).
cspell.jsonNew single-source spell dictionary + ignore paths.
CODESTYLE.mdUpdates clean-compile/lint/spell guidance to match CI + cspell.json.
AGENTS.mdRe-points CI/CD canon to WORKFLOW.md and updates merge/release semantics accordingly.
.github/workflows/validate-task.ymlNew reusable validation gate (unit tests + CSharpier/dotnet-format/markdownlint/cspell/actionlint).
.github/workflows/test-pull-request.ymlReworked CI entry workflow to run on push + produce the ruleset-bound aggregator check.
.github/workflows/publish-release.ymlReworked publisher to be branch-scoped + shipped-input path gated; uses validate-task gate.
.github/workflows/build-release-task.ymlReworked build/version/publish/release reusable task; adds OIDC NuGet trusted publishing and simplified asset handling.
.github/workflows/run-periodic-codegen-pull-request.ymlUpdates description/comments; maintains scheduled daily codegen entry workflow.
.github/workflows/run-codegen-pull-request-task.ymlUpdates documentation/comments around per-branch codegen PR creation.
.github/workflows/merge-bot-pull-request.ymlRemoves semver-major NuGet exception; makes Dependabot auto-merge unconditional on green checks.
.github/workflows/get-version-task.ymlDeleted (versioning now handled inside build-release-task.yml).
.github/workflows/build-nugetlibrary-task.ymlDeleted (logic folded into build-release-task.yml).
.github/workflows/build-datebadge-task.ymlDeleted (BYOB date badge removed).

Comment threadWORKFLOW.md Outdated
Comment threadWORKFLOW.md Outdated
Comment thread.github/workflows/build-release-task.yml Outdated
Comment thread.github/workflows/validate-task.yml Outdated
Comment thread.github/workflows/test-pull-request.yml Outdated
ptr727and others added 2 commits June 27, 2026 14:26
The project sets GeneratePackageOnBuild, so the build emits the .nupkg
(+ .snupkg). Running dotnet pack on top of that double-packs and fails to
find the assembly under the .artifacts layout ("LanguageTags.dll to be
packed was not found"). Build instead, redirecting OutputPath and
PackageOutputPath out of .artifacts, matching the prior working task.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…ctionlint
- WORKFLOW.md: frame dependency-bump exclusion as a deliberate churn-avoidance
policy, not a "no compiled code change" technical invariant (x2).
- build-release-task: correct the smoke validate-release skip rationale; smoke
can run on main, so the reason is "smoke never publishes", not "never main".
- validate-task: verify the actionlint release tarball against its published
SHA-256 before extracting/executing it, closing the unchecked-download path.
- test-pull-request: make the no-pull_request-trigger fork constraint and the
maintainer workflow explicit in the header.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 27, 2026 21:31

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 23 out of 23 changed files in this pull request and generated 2 comments.

Comment thread.github/workflows/build-release-task.yml
Comment threadREADME.md Outdated
ptr727and others added 2 commits June 27, 2026 14:39
… action
- Replace Unicode arrows (->) and an ellipsis (...) in README.md and the
dependabot.yml comments with ASCII, per AGENTS.md "no Unicode arrows / no
ellipsis character".
- Lint workflows via the SHA-pinned raven-actions/actionlint action (vendors
actionlint + shellcheck) instead of a hand-rolled curl download, matching
the repo's pin-every-action convention and dropping manual checksum upkeep.
The snupkg comment is a false positive: dotnet nuget push auto-pushes the
co-located .snupkg to nuget.org (no --no-symbols), as the workflow documents.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Comments:
- Trim verbose workflow comments to the non-obvious points. Move the snupkg
note onto the push step, name GitCommitId where comments said "built
commit", and make the artifact-delete gate explicit.
- Restructure publish-release's top comment into bullets, and drop prose
semicolons and inline spec-section refs (D4.6 etc.) across the workflows.
- Reflow dependabot.yml comments to ~120-column structured lines.
- AGENTS.md comments rule now prefers structure over a long prose paragraph.
Scope docs to C# and Actions, dropping shared-template carryover:
- Remove the Python section and the multi-language / derived-repo framing
from CODESTYLE.md; de-template .editorconfig, copilot-instructions.md, and
.vscode/tasks.json.
- Prune orphaned Python-tooling words from cspell.json.
tasks.json: add "Run Codegen" and "Codegen and Format" (codegen then
CSharpier, since generated line lengths are not always CSharpier-aligned).
README contributing/setup now point to WORKFLOW.md, CODESTYLE.md, and
repo-config (maintainer edit).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 27, 2026 22:57

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 27 out of 27 changed files in this pull request and generated 2 comments.

Comment threadWORKFLOW.md Outdated
Comment threadcspell.json Outdated
- Reconcile the Dependabot/fork validation contract: there is no pull_request
trigger, so Dependabot PRs (in-repo branches) validate via their push, and
only forks (which cannot push) need maintainer action. Previously the doc
claimed a base-resolved pull_request fallback that does not exist.
- cspell: set language to en-US to match the documented US-English rule.
- Remove the temporary go-live adoption note.
- Drop the project-type generality section and the multi-shape / portability
framing, scoping the spec to this NuGet library's workflows.
- Fix a broken concurrency sentence and clause-joining semicolons.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 27 out of 27 changed files in this pull request and generated 2 comments.

Comment thread.github/workflows/build-release-task.yml
Comment threadrepo-config/configure.sh
ptr727and others added 2 commits June 27, 2026 16:19
check_secrets now passes --paginate to the actions/secrets and
dependabot/secrets endpoints, so a repo with more than 30 secrets cannot miss
a required name and report a false failure.
The NuGet/login output finding is a false positive: the pinned
NuGet/login@v1.2.0 action.yml outputs NUGET_API_KEY, which the push step uses.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Tighten the verbose narrative in sections 0 and 3 and the longest guarantees
(D4.6, D8.3), drop redundant re-explanation, and remove clause-joining
semicolons. All guarantees (D0-D10) and scenarios (S1-S15) are preserved.
Also fix a model-paragraph inconsistency: it listed a runtime-dependency
update as auto-publishing, but dependency bumps are excluded from the
shipped-input inclusion list. The package publishes on a shipped-input change.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 27, 2026 23:28

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 27 out of 27 changed files in this pull request and generated 4 comments.

Comment thread.github/workflows/test-pull-request.yml
Comment threadrepo-config/configure.sh Outdated
Comment threadrepo-config/README.md
Comment threadrepo-config/README.md Outdated
- test-pull-request: restrict the push trigger to branches ['**'] so release
tags never re-run CI (the contract is CI for every branch, not tags).
- configure.sh and repo-config README: both check and apply use admin-only
rulesets/secrets endpoints, so check needs an admin-authenticated gh token
too (read-only, but not the default CI token). Corrected the misleading
"safe for CI" wording.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@ptr727
ptr727 merged commit b945a2b into developJun 28, 2026
10 checks passed
@ptr727
ptr727 deleted the feature/branch-scoped-cicd branch June 28, 2026 00:18
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Revert to branch-scoped self-publishing CI/CD - #204

Merged
ptr727 merged 9 commits into
developfrom
feature/branch-scoped-cicd
Jun 28, 2026
Merged

Revert to branch-scoped self-publishing CI/CD#204
ptr727 merged 9 commits into
developfrom
feature/branch-scoped-cicd

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Summary

Replaces the shared project-template CI/CD with a branch-scoped, self-sufficient workflow set written for this repo. One run targets the branch it was triggered on; NBGV versions it natively; a reusable validate-task (unit tests + lint) gates both the pull request and the publisher; and a shipped-input push to main/develop self-publishes (main stable, develop prerelease) with no schedule or PUBLISH_ON_MERGE.

Changes

  • WORKFLOW.md - canonical branch-scoped CI/CD spec + audit methodology (5A static / 5B trace / 5C live / 5D config).
  • validate-task.yml - unit-test + lint (csharpier, dotnet format, markdownlint, cspell, actionlint); the PR gate and the publish job both need: it, so nothing publishes that would fail the PR.
  • Rewrote publish-release / test-pull-request / build-release-task; deleted get-version / build-nugetlibrary / build-datebadge.
  • NuGet publishing is keyless via OIDC trusted publishing (NUGET_USERNAME, no API key).
  • repo-config/ - rulesets, settings, and configure.sh apply|check (the 5D config audit).
  • cspell.json - single-source spell dictionary (extension + CLI + CI read it).
  • Reconciled AGENTS.md / CODESTYLE.md / README.md / HISTORY.md; bumped to 1.5.

Go-live coordination (maintainer)

  • The aggregator required check is renamed to Check pull request workflow status job. The live ruleset still requires the old name, so repo-config/configure.sh apply must run in lockstep with merging this PR (it also fixes delete_branch_on_merge). Until then the live required check is satisfied by the base-resolved old workflow.
  • version.json is bumped (1.4 -> 1.5), a shipped input, so merging this to develop will auto-publish a 1.5 prerelease to NuGet. Intended, but flagging it.

🤖 Generated with Claude Code

Replace the shared project-template workflow model with a branch-scoped,
self-sufficient set written for this repo. One run targets the branch it was
triggered on; NBGV versions it natively (no IGNORE_GITHUB_REF / checkout -B);
a reusable validate-task (unit tests + lint) gates both the pull request and
the publisher; and a shipped-input push to main/develop self-publishes (main
stable, develop prerelease) with no schedule or PUBLISH_ON_MERGE.
- Add WORKFLOW.md: canonical branch-scoped CI/CD spec plus audit methodology.
- Add validate-task.yml (unit-test plus lint: csharpier, dotnet format,
markdownlint, cspell, actionlint); PR gate and publish job both need it.
- Rewrite publish-release/test-pull-request/build-release-task; delete the
get-version/build-nugetlibrary/build-datebadge tasks.
- NuGet publishing is keyless via OIDC trusted publishing (NUGET_USERNAME, no
long-lived API key).
- Add repo-config/ (rulesets, settings, configure.sh apply|check 5D audit) and
cspell.json (single-source spell dictionary).
- Reconcile AGENTS.md/CODESTYLE.md/README.md/HISTORY.md; bump version to 1.5.
Rename the required status check to "Check pull request workflow status job";
the live ruleset must be applied in lockstep (repo-config/configure.sh apply).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 27, 2026 21:21

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR replaces the template-derived, matrix/scheduled CI/CD with a repo-specific, branch-scoped workflow set where each run targets only the triggering branch (main = stable, develop = prerelease), reusing a single validate-task gate for both PR validation and publishing. It also codifies repo settings/rulesets/secrets-as-names under repo-config/ and updates docs/versioning to reflect the new operational contract.

Changes:

  • Added a canonical CI/CD contract + audit methodology (WORKFLOW.md) and a config-as-code audit/apply toolchain (repo-config/).
  • Introduced validate-task.yml (unit test + lint suite) and rewired test-pull-request.yml / publish-release.yml / build-release-task.yml around branch-scoped self-publishing + OIDC NuGet trusted publishing.
  • Updated release/docs metadata (bump version.json to 1.5; refreshed README.md, HISTORY.md, AGENTS.md, CODESTYLE.md; centralized spelling words in cspell.json and removed workspace-local dictionary).

Reviewed changes

Copilot reviewed 23 out of 23 changed files in this pull request and generated 5 comments.

Show a summary per file
FileDescription
WORKFLOW.mdNew end-to-end CI/CD contract (architecture, guarantees, and audit methodology).
version.jsonBumps version floor from 1.4 to 1.5.
repo-config/settings.jsonDeclares desired repository settings (auto-merge, merge methods, delete-branch-on-merge).
repo-config/ruleset-main.jsonCodifies main ruleset (merge-commit only, required check, signatures, strict off).
repo-config/ruleset-develop.jsonCodifies develop ruleset (squash-only + linear history, required check, signatures, strict off).
repo-config/README.mdDocuments config-as-code scope and the required-check rename lockstep.
repo-config/configure.shAdds `apply
README.mdUpdates release notes, CI/CD description, required-check name, and publishing/auth model.
HISTORY.mdAdds 1.5 entry describing CI/CD revert/rework and keyless publishing.
LanguageTags.code-workspaceRemoves embedded cSpell word list (now centralized in cspell.json).
cspell.jsonNew single-source spell dictionary + ignore paths.
CODESTYLE.mdUpdates clean-compile/lint/spell guidance to match CI + cspell.json.
AGENTS.mdRe-points CI/CD canon to WORKFLOW.md and updates merge/release semantics accordingly.
.github/workflows/validate-task.ymlNew reusable validation gate (unit tests + CSharpier/dotnet-format/markdownlint/cspell/actionlint).
.github/workflows/test-pull-request.ymlReworked CI entry workflow to run on push + produce the ruleset-bound aggregator check.
.github/workflows/publish-release.ymlReworked publisher to be branch-scoped + shipped-input path gated; uses validate-task gate.
.github/workflows/build-release-task.ymlReworked build/version/publish/release reusable task; adds OIDC NuGet trusted publishing and simplified asset handling.
.github/workflows/run-periodic-codegen-pull-request.ymlUpdates description/comments; maintains scheduled daily codegen entry workflow.
.github/workflows/run-codegen-pull-request-task.ymlUpdates documentation/comments around per-branch codegen PR creation.
.github/workflows/merge-bot-pull-request.ymlRemoves semver-major NuGet exception; makes Dependabot auto-merge unconditional on green checks.
.github/workflows/get-version-task.ymlDeleted (versioning now handled inside build-release-task.yml).
.github/workflows/build-nugetlibrary-task.ymlDeleted (logic folded into build-release-task.yml).
.github/workflows/build-datebadge-task.ymlDeleted (BYOB date badge removed).

Comment threadWORKFLOW.md Outdated
Comment threadWORKFLOW.md Outdated
Comment thread.github/workflows/build-release-task.yml Outdated
Comment thread.github/workflows/validate-task.yml Outdated
Comment thread.github/workflows/test-pull-request.yml Outdated
ptr727and others added 2 commits June 27, 2026 14:26
The project sets GeneratePackageOnBuild, so the build emits the .nupkg
(+ .snupkg). Running dotnet pack on top of that double-packs and fails to
find the assembly under the .artifacts layout ("LanguageTags.dll to be
packed was not found"). Build instead, redirecting OutputPath and
PackageOutputPath out of .artifacts, matching the prior working task.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…ctionlint
- WORKFLOW.md: frame dependency-bump exclusion as a deliberate churn-avoidance
policy, not a "no compiled code change" technical invariant (x2).
- build-release-task: correct the smoke validate-release skip rationale; smoke
can run on main, so the reason is "smoke never publishes", not "never main".
- validate-task: verify the actionlint release tarball against its published
SHA-256 before extracting/executing it, closing the unchecked-download path.
- test-pull-request: make the no-pull_request-trigger fork constraint and the
maintainer workflow explicit in the header.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 27, 2026 21:31

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 23 out of 23 changed files in this pull request and generated 2 comments.

Comment thread.github/workflows/build-release-task.yml
Comment threadREADME.md Outdated
ptr727and others added 2 commits June 27, 2026 14:39
… action
- Replace Unicode arrows (->) and an ellipsis (...) in README.md and the
dependabot.yml comments with ASCII, per AGENTS.md "no Unicode arrows / no
ellipsis character".
- Lint workflows via the SHA-pinned raven-actions/actionlint action (vendors
actionlint + shellcheck) instead of a hand-rolled curl download, matching
the repo's pin-every-action convention and dropping manual checksum upkeep.
The snupkg comment is a false positive: dotnet nuget push auto-pushes the
co-located .snupkg to nuget.org (no --no-symbols), as the workflow documents.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Comments:
- Trim verbose workflow comments to the non-obvious points. Move the snupkg
note onto the push step, name GitCommitId where comments said "built
commit", and make the artifact-delete gate explicit.
- Restructure publish-release's top comment into bullets, and drop prose
semicolons and inline spec-section refs (D4.6 etc.) across the workflows.
- Reflow dependabot.yml comments to ~120-column structured lines.
- AGENTS.md comments rule now prefers structure over a long prose paragraph.
Scope docs to C# and Actions, dropping shared-template carryover:
- Remove the Python section and the multi-language / derived-repo framing
from CODESTYLE.md; de-template .editorconfig, copilot-instructions.md, and
.vscode/tasks.json.
- Prune orphaned Python-tooling words from cspell.json.
tasks.json: add "Run Codegen" and "Codegen and Format" (codegen then
CSharpier, since generated line lengths are not always CSharpier-aligned).
README contributing/setup now point to WORKFLOW.md, CODESTYLE.md, and
repo-config (maintainer edit).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 27, 2026 22:57

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 27 out of 27 changed files in this pull request and generated 2 comments.

Comment threadWORKFLOW.md Outdated
Comment threadcspell.json Outdated
- Reconcile the Dependabot/fork validation contract: there is no pull_request
trigger, so Dependabot PRs (in-repo branches) validate via their push, and
only forks (which cannot push) need maintainer action. Previously the doc
claimed a base-resolved pull_request fallback that does not exist.
- cspell: set language to en-US to match the documented US-English rule.
- Remove the temporary go-live adoption note.
- Drop the project-type generality section and the multi-shape / portability
framing, scoping the spec to this NuGet library's workflows.
- Fix a broken concurrency sentence and clause-joining semicolons.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 27 out of 27 changed files in this pull request and generated 2 comments.

Comment thread.github/workflows/build-release-task.yml
Comment threadrepo-config/configure.sh
ptr727and others added 2 commits June 27, 2026 16:19
check_secrets now passes --paginate to the actions/secrets and
dependabot/secrets endpoints, so a repo with more than 30 secrets cannot miss
a required name and report a false failure.
The NuGet/login output finding is a false positive: the pinned
NuGet/login@v1.2.0 action.yml outputs NUGET_API_KEY, which the push step uses.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Tighten the verbose narrative in sections 0 and 3 and the longest guarantees
(D4.6, D8.3), drop redundant re-explanation, and remove clause-joining
semicolons. All guarantees (D0-D10) and scenarios (S1-S15) are preserved.
Also fix a model-paragraph inconsistency: it listed a runtime-dependency
update as auto-publishing, but dependency bumps are excluded from the
shipped-input inclusion list. The package publishes on a shipped-input change.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 27, 2026 23:28

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 27 out of 27 changed files in this pull request and generated 4 comments.

Comment thread.github/workflows/test-pull-request.yml
Comment threadrepo-config/configure.sh Outdated
Comment threadrepo-config/README.md
Comment threadrepo-config/README.md Outdated
- test-pull-request: restrict the push trigger to branches ['**'] so release
tags never re-run CI (the contract is CI for every branch, not tags).
- configure.sh and repo-config README: both check and apply use admin-only
rulesets/secrets endpoints, so check needs an admin-authenticated gh token
too (read-only, but not the default CI token). Corrected the misleading
"safe for CI" wording.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@ptr727
ptr727 merged commit b945a2b into developJun 28, 2026
10 checks passed
@ptr727
ptr727 deleted the feature/branch-scoped-cicd branch June 28, 2026 00:18
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Revert to branch-scoped self-publishing CI/CD - #204

Merged
ptr727 merged 9 commits into
developfrom
feature/branch-scoped-cicd
Jun 28, 2026
Merged

Revert to branch-scoped self-publishing CI/CD#204
ptr727 merged 9 commits into
developfrom
feature/branch-scoped-cicd

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Summary

Replaces the shared project-template CI/CD with a branch-scoped, self-sufficient workflow set written for this repo. One run targets the branch it was triggered on; NBGV versions it natively; a reusable validate-task (unit tests + lint) gates both the pull request and the publisher; and a shipped-input push to main/develop self-publishes (main stable, develop prerelease) with no schedule or PUBLISH_ON_MERGE.

Changes

  • WORKFLOW.md - canonical branch-scoped CI/CD spec + audit methodology (5A static / 5B trace / 5C live / 5D config).
  • validate-task.yml - unit-test + lint (csharpier, dotnet format, markdownlint, cspell, actionlint); the PR gate and the publish job both need: it, so nothing publishes that would fail the PR.
  • Rewrote publish-release / test-pull-request / build-release-task; deleted get-version / build-nugetlibrary / build-datebadge.
  • NuGet publishing is keyless via OIDC trusted publishing (NUGET_USERNAME, no API key).
  • repo-config/ - rulesets, settings, and configure.sh apply|check (the 5D config audit).
  • cspell.json - single-source spell dictionary (extension + CLI + CI read it).
  • Reconciled AGENTS.md / CODESTYLE.md / README.md / HISTORY.md; bumped to 1.5.

Go-live coordination (maintainer)

  • The aggregator required check is renamed to Check pull request workflow status job. The live ruleset still requires the old name, so repo-config/configure.sh apply must run in lockstep with merging this PR (it also fixes delete_branch_on_merge). Until then the live required check is satisfied by the base-resolved old workflow.
  • version.json is bumped (1.4 -> 1.5), a shipped input, so merging this to develop will auto-publish a 1.5 prerelease to NuGet. Intended, but flagging it.

🤖 Generated with Claude Code

Replace the shared project-template workflow model with a branch-scoped,
self-sufficient set written for this repo. One run targets the branch it was
triggered on; NBGV versions it natively (no IGNORE_GITHUB_REF / checkout -B);
a reusable validate-task (unit tests + lint) gates both the pull request and
the publisher; and a shipped-input push to main/develop self-publishes (main
stable, develop prerelease) with no schedule or PUBLISH_ON_MERGE.
- Add WORKFLOW.md: canonical branch-scoped CI/CD spec plus audit methodology.
- Add validate-task.yml (unit-test plus lint: csharpier, dotnet format,
markdownlint, cspell, actionlint); PR gate and publish job both need it.
- Rewrite publish-release/test-pull-request/build-release-task; delete the
get-version/build-nugetlibrary/build-datebadge tasks.
- NuGet publishing is keyless via OIDC trusted publishing (NUGET_USERNAME, no
long-lived API key).
- Add repo-config/ (rulesets, settings, configure.sh apply|check 5D audit) and
cspell.json (single-source spell dictionary).
- Reconcile AGENTS.md/CODESTYLE.md/README.md/HISTORY.md; bump version to 1.5.
Rename the required status check to "Check pull request workflow status job";
the live ruleset must be applied in lockstep (repo-config/configure.sh apply).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 27, 2026 21:21

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR replaces the template-derived, matrix/scheduled CI/CD with a repo-specific, branch-scoped workflow set where each run targets only the triggering branch (main = stable, develop = prerelease), reusing a single validate-task gate for both PR validation and publishing. It also codifies repo settings/rulesets/secrets-as-names under repo-config/ and updates docs/versioning to reflect the new operational contract.

Changes:

  • Added a canonical CI/CD contract + audit methodology (WORKFLOW.md) and a config-as-code audit/apply toolchain (repo-config/).
  • Introduced validate-task.yml (unit test + lint suite) and rewired test-pull-request.yml / publish-release.yml / build-release-task.yml around branch-scoped self-publishing + OIDC NuGet trusted publishing.
  • Updated release/docs metadata (bump version.json to 1.5; refreshed README.md, HISTORY.md, AGENTS.md, CODESTYLE.md; centralized spelling words in cspell.json and removed workspace-local dictionary).

Reviewed changes

Copilot reviewed 23 out of 23 changed files in this pull request and generated 5 comments.

Show a summary per file
FileDescription
WORKFLOW.mdNew end-to-end CI/CD contract (architecture, guarantees, and audit methodology).
version.jsonBumps version floor from 1.4 to 1.5.
repo-config/settings.jsonDeclares desired repository settings (auto-merge, merge methods, delete-branch-on-merge).
repo-config/ruleset-main.jsonCodifies main ruleset (merge-commit only, required check, signatures, strict off).
repo-config/ruleset-develop.jsonCodifies develop ruleset (squash-only + linear history, required check, signatures, strict off).
repo-config/README.mdDocuments config-as-code scope and the required-check rename lockstep.
repo-config/configure.shAdds `apply
README.mdUpdates release notes, CI/CD description, required-check name, and publishing/auth model.
HISTORY.mdAdds 1.5 entry describing CI/CD revert/rework and keyless publishing.
LanguageTags.code-workspaceRemoves embedded cSpell word list (now centralized in cspell.json).
cspell.jsonNew single-source spell dictionary + ignore paths.
CODESTYLE.mdUpdates clean-compile/lint/spell guidance to match CI + cspell.json.
AGENTS.mdRe-points CI/CD canon to WORKFLOW.md and updates merge/release semantics accordingly.
.github/workflows/validate-task.ymlNew reusable validation gate (unit tests + CSharpier/dotnet-format/markdownlint/cspell/actionlint).
.github/workflows/test-pull-request.ymlReworked CI entry workflow to run on push + produce the ruleset-bound aggregator check.
.github/workflows/publish-release.ymlReworked publisher to be branch-scoped + shipped-input path gated; uses validate-task gate.
.github/workflows/build-release-task.ymlReworked build/version/publish/release reusable task; adds OIDC NuGet trusted publishing and simplified asset handling.
.github/workflows/run-periodic-codegen-pull-request.ymlUpdates description/comments; maintains scheduled daily codegen entry workflow.
.github/workflows/run-codegen-pull-request-task.ymlUpdates documentation/comments around per-branch codegen PR creation.
.github/workflows/merge-bot-pull-request.ymlRemoves semver-major NuGet exception; makes Dependabot auto-merge unconditional on green checks.
.github/workflows/get-version-task.ymlDeleted (versioning now handled inside build-release-task.yml).
.github/workflows/build-nugetlibrary-task.ymlDeleted (logic folded into build-release-task.yml).
.github/workflows/build-datebadge-task.ymlDeleted (BYOB date badge removed).

Comment threadWORKFLOW.md Outdated
Comment threadWORKFLOW.md Outdated
Comment thread.github/workflows/build-release-task.yml Outdated
Comment thread.github/workflows/validate-task.yml Outdated
Comment thread.github/workflows/test-pull-request.yml Outdated
ptr727and others added 2 commits June 27, 2026 14:26
The project sets GeneratePackageOnBuild, so the build emits the .nupkg
(+ .snupkg). Running dotnet pack on top of that double-packs and fails to
find the assembly under the .artifacts layout ("LanguageTags.dll to be
packed was not found"). Build instead, redirecting OutputPath and
PackageOutputPath out of .artifacts, matching the prior working task.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…ctionlint
- WORKFLOW.md: frame dependency-bump exclusion as a deliberate churn-avoidance
policy, not a "no compiled code change" technical invariant (x2).
- build-release-task: correct the smoke validate-release skip rationale; smoke
can run on main, so the reason is "smoke never publishes", not "never main".
- validate-task: verify the actionlint release tarball against its published
SHA-256 before extracting/executing it, closing the unchecked-download path.
- test-pull-request: make the no-pull_request-trigger fork constraint and the
maintainer workflow explicit in the header.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 27, 2026 21:31

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 23 out of 23 changed files in this pull request and generated 2 comments.

Comment thread.github/workflows/build-release-task.yml
Comment threadREADME.md Outdated
ptr727and others added 2 commits June 27, 2026 14:39
… action
- Replace Unicode arrows (->) and an ellipsis (...) in README.md and the
dependabot.yml comments with ASCII, per AGENTS.md "no Unicode arrows / no
ellipsis character".
- Lint workflows via the SHA-pinned raven-actions/actionlint action (vendors
actionlint + shellcheck) instead of a hand-rolled curl download, matching
the repo's pin-every-action convention and dropping manual checksum upkeep.
The snupkg comment is a false positive: dotnet nuget push auto-pushes the
co-located .snupkg to nuget.org (no --no-symbols), as the workflow documents.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Comments:
- Trim verbose workflow comments to the non-obvious points. Move the snupkg
note onto the push step, name GitCommitId where comments said "built
commit", and make the artifact-delete gate explicit.
- Restructure publish-release's top comment into bullets, and drop prose
semicolons and inline spec-section refs (D4.6 etc.) across the workflows.
- Reflow dependabot.yml comments to ~120-column structured lines.
- AGENTS.md comments rule now prefers structure over a long prose paragraph.
Scope docs to C# and Actions, dropping shared-template carryover:
- Remove the Python section and the multi-language / derived-repo framing
from CODESTYLE.md; de-template .editorconfig, copilot-instructions.md, and
.vscode/tasks.json.
- Prune orphaned Python-tooling words from cspell.json.
tasks.json: add "Run Codegen" and "Codegen and Format" (codegen then
CSharpier, since generated line lengths are not always CSharpier-aligned).
README contributing/setup now point to WORKFLOW.md, CODESTYLE.md, and
repo-config (maintainer edit).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 27, 2026 22:57

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 27 out of 27 changed files in this pull request and generated 2 comments.

Comment threadWORKFLOW.md Outdated
Comment threadcspell.json Outdated
- Reconcile the Dependabot/fork validation contract: there is no pull_request
trigger, so Dependabot PRs (in-repo branches) validate via their push, and
only forks (which cannot push) need maintainer action. Previously the doc
claimed a base-resolved pull_request fallback that does not exist.
- cspell: set language to en-US to match the documented US-English rule.
- Remove the temporary go-live adoption note.
- Drop the project-type generality section and the multi-shape / portability
framing, scoping the spec to this NuGet library's workflows.
- Fix a broken concurrency sentence and clause-joining semicolons.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 27 out of 27 changed files in this pull request and generated 2 comments.

Comment thread.github/workflows/build-release-task.yml
Comment threadrepo-config/configure.sh
ptr727and others added 2 commits June 27, 2026 16:19
check_secrets now passes --paginate to the actions/secrets and
dependabot/secrets endpoints, so a repo with more than 30 secrets cannot miss
a required name and report a false failure.
The NuGet/login output finding is a false positive: the pinned
NuGet/login@v1.2.0 action.yml outputs NUGET_API_KEY, which the push step uses.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Tighten the verbose narrative in sections 0 and 3 and the longest guarantees
(D4.6, D8.3), drop redundant re-explanation, and remove clause-joining
semicolons. All guarantees (D0-D10) and scenarios (S1-S15) are preserved.
Also fix a model-paragraph inconsistency: it listed a runtime-dependency
update as auto-publishing, but dependency bumps are excluded from the
shipped-input inclusion list. The package publishes on a shipped-input change.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 27, 2026 23:28

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 27 out of 27 changed files in this pull request and generated 4 comments.

Comment thread.github/workflows/test-pull-request.yml
Comment threadrepo-config/configure.sh Outdated
Comment threadrepo-config/README.md
Comment threadrepo-config/README.md Outdated
- test-pull-request: restrict the push trigger to branches ['**'] so release
tags never re-run CI (the contract is CI for every branch, not tags).
- configure.sh and repo-config README: both check and apply use admin-only
rulesets/secrets endpoints, so check needs an admin-authenticated gh token
too (read-only, but not the default CI token). Corrected the misleading
"safe for CI" wording.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@ptr727
ptr727 merged commit b945a2b into developJun 28, 2026
10 checks passed
@ptr727
ptr727 deleted the feature/branch-scoped-cicd branch June 28, 2026 00:18
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Revert to branch-scoped self-publishing CI/CD - #204

Merged
ptr727 merged 9 commits into
developfrom
feature/branch-scoped-cicd
Jun 28, 2026
Merged

Revert to branch-scoped self-publishing CI/CD#204
ptr727 merged 9 commits into
developfrom
feature/branch-scoped-cicd

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Summary

Replaces the shared project-template CI/CD with a branch-scoped, self-sufficient workflow set written for this repo. One run targets the branch it was triggered on; NBGV versions it natively; a reusable validate-task (unit tests + lint) gates both the pull request and the publisher; and a shipped-input push to main/develop self-publishes (main stable, develop prerelease) with no schedule or PUBLISH_ON_MERGE.

Changes

  • WORKFLOW.md - canonical branch-scoped CI/CD spec + audit methodology (5A static / 5B trace / 5C live / 5D config).
  • validate-task.yml - unit-test + lint (csharpier, dotnet format, markdownlint, cspell, actionlint); the PR gate and the publish job both need: it, so nothing publishes that would fail the PR.
  • Rewrote publish-release / test-pull-request / build-release-task; deleted get-version / build-nugetlibrary / build-datebadge.
  • NuGet publishing is keyless via OIDC trusted publishing (NUGET_USERNAME, no API key).
  • repo-config/ - rulesets, settings, and configure.sh apply|check (the 5D config audit).
  • cspell.json - single-source spell dictionary (extension + CLI + CI read it).
  • Reconciled AGENTS.md / CODESTYLE.md / README.md / HISTORY.md; bumped to 1.5.

Go-live coordination (maintainer)

  • The aggregator required check is renamed to Check pull request workflow status job. The live ruleset still requires the old name, so repo-config/configure.sh apply must run in lockstep with merging this PR (it also fixes delete_branch_on_merge). Until then the live required check is satisfied by the base-resolved old workflow.
  • version.json is bumped (1.4 -> 1.5), a shipped input, so merging this to develop will auto-publish a 1.5 prerelease to NuGet. Intended, but flagging it.

🤖 Generated with Claude Code

Replace the shared project-template workflow model with a branch-scoped,
self-sufficient set written for this repo. One run targets the branch it was
triggered on; NBGV versions it natively (no IGNORE_GITHUB_REF / checkout -B);
a reusable validate-task (unit tests + lint) gates both the pull request and
the publisher; and a shipped-input push to main/develop self-publishes (main
stable, develop prerelease) with no schedule or PUBLISH_ON_MERGE.
- Add WORKFLOW.md: canonical branch-scoped CI/CD spec plus audit methodology.
- Add validate-task.yml (unit-test plus lint: csharpier, dotnet format,
markdownlint, cspell, actionlint); PR gate and publish job both need it.
- Rewrite publish-release/test-pull-request/build-release-task; delete the
get-version/build-nugetlibrary/build-datebadge tasks.
- NuGet publishing is keyless via OIDC trusted publishing (NUGET_USERNAME, no
long-lived API key).
- Add repo-config/ (rulesets, settings, configure.sh apply|check 5D audit) and
cspell.json (single-source spell dictionary).
- Reconcile AGENTS.md/CODESTYLE.md/README.md/HISTORY.md; bump version to 1.5.
Rename the required status check to "Check pull request workflow status job";
the live ruleset must be applied in lockstep (repo-config/configure.sh apply).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 27, 2026 21:21

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR replaces the template-derived, matrix/scheduled CI/CD with a repo-specific, branch-scoped workflow set where each run targets only the triggering branch (main = stable, develop = prerelease), reusing a single validate-task gate for both PR validation and publishing. It also codifies repo settings/rulesets/secrets-as-names under repo-config/ and updates docs/versioning to reflect the new operational contract.

Changes:

  • Added a canonical CI/CD contract + audit methodology (WORKFLOW.md) and a config-as-code audit/apply toolchain (repo-config/).
  • Introduced validate-task.yml (unit test + lint suite) and rewired test-pull-request.yml / publish-release.yml / build-release-task.yml around branch-scoped self-publishing + OIDC NuGet trusted publishing.
  • Updated release/docs metadata (bump version.json to 1.5; refreshed README.md, HISTORY.md, AGENTS.md, CODESTYLE.md; centralized spelling words in cspell.json and removed workspace-local dictionary).

Reviewed changes

Copilot reviewed 23 out of 23 changed files in this pull request and generated 5 comments.

Show a summary per file
FileDescription
WORKFLOW.mdNew end-to-end CI/CD contract (architecture, guarantees, and audit methodology).
version.jsonBumps version floor from 1.4 to 1.5.
repo-config/settings.jsonDeclares desired repository settings (auto-merge, merge methods, delete-branch-on-merge).
repo-config/ruleset-main.jsonCodifies main ruleset (merge-commit only, required check, signatures, strict off).
repo-config/ruleset-develop.jsonCodifies develop ruleset (squash-only + linear history, required check, signatures, strict off).
repo-config/README.mdDocuments config-as-code scope and the required-check rename lockstep.
repo-config/configure.shAdds `apply
README.mdUpdates release notes, CI/CD description, required-check name, and publishing/auth model.
HISTORY.mdAdds 1.5 entry describing CI/CD revert/rework and keyless publishing.
LanguageTags.code-workspaceRemoves embedded cSpell word list (now centralized in cspell.json).
cspell.jsonNew single-source spell dictionary + ignore paths.
CODESTYLE.mdUpdates clean-compile/lint/spell guidance to match CI + cspell.json.
AGENTS.mdRe-points CI/CD canon to WORKFLOW.md and updates merge/release semantics accordingly.
.github/workflows/validate-task.ymlNew reusable validation gate (unit tests + CSharpier/dotnet-format/markdownlint/cspell/actionlint).
.github/workflows/test-pull-request.ymlReworked CI entry workflow to run on push + produce the ruleset-bound aggregator check.
.github/workflows/publish-release.ymlReworked publisher to be branch-scoped + shipped-input path gated; uses validate-task gate.
.github/workflows/build-release-task.ymlReworked build/version/publish/release reusable task; adds OIDC NuGet trusted publishing and simplified asset handling.
.github/workflows/run-periodic-codegen-pull-request.ymlUpdates description/comments; maintains scheduled daily codegen entry workflow.
.github/workflows/run-codegen-pull-request-task.ymlUpdates documentation/comments around per-branch codegen PR creation.
.github/workflows/merge-bot-pull-request.ymlRemoves semver-major NuGet exception; makes Dependabot auto-merge unconditional on green checks.
.github/workflows/get-version-task.ymlDeleted (versioning now handled inside build-release-task.yml).
.github/workflows/build-nugetlibrary-task.ymlDeleted (logic folded into build-release-task.yml).
.github/workflows/build-datebadge-task.ymlDeleted (BYOB date badge removed).

Comment threadWORKFLOW.md Outdated
Comment threadWORKFLOW.md Outdated
Comment thread.github/workflows/build-release-task.yml Outdated
Comment thread.github/workflows/validate-task.yml Outdated
Comment thread.github/workflows/test-pull-request.yml Outdated
ptr727and others added 2 commits June 27, 2026 14:26
The project sets GeneratePackageOnBuild, so the build emits the .nupkg
(+ .snupkg). Running dotnet pack on top of that double-packs and fails to
find the assembly under the .artifacts layout ("LanguageTags.dll to be
packed was not found"). Build instead, redirecting OutputPath and
PackageOutputPath out of .artifacts, matching the prior working task.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…ctionlint
- WORKFLOW.md: frame dependency-bump exclusion as a deliberate churn-avoidance
policy, not a "no compiled code change" technical invariant (x2).
- build-release-task: correct the smoke validate-release skip rationale; smoke
can run on main, so the reason is "smoke never publishes", not "never main".
- validate-task: verify the actionlint release tarball against its published
SHA-256 before extracting/executing it, closing the unchecked-download path.
- test-pull-request: make the no-pull_request-trigger fork constraint and the
maintainer workflow explicit in the header.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 27, 2026 21:31

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 23 out of 23 changed files in this pull request and generated 2 comments.

Comment thread.github/workflows/build-release-task.yml
Comment threadREADME.md Outdated
ptr727and others added 2 commits June 27, 2026 14:39
… action
- Replace Unicode arrows (->) and an ellipsis (...) in README.md and the
dependabot.yml comments with ASCII, per AGENTS.md "no Unicode arrows / no
ellipsis character".
- Lint workflows via the SHA-pinned raven-actions/actionlint action (vendors
actionlint + shellcheck) instead of a hand-rolled curl download, matching
the repo's pin-every-action convention and dropping manual checksum upkeep.
The snupkg comment is a false positive: dotnet nuget push auto-pushes the
co-located .snupkg to nuget.org (no --no-symbols), as the workflow documents.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Comments:
- Trim verbose workflow comments to the non-obvious points. Move the snupkg
note onto the push step, name GitCommitId where comments said "built
commit", and make the artifact-delete gate explicit.
- Restructure publish-release's top comment into bullets, and drop prose
semicolons and inline spec-section refs (D4.6 etc.) across the workflows.
- Reflow dependabot.yml comments to ~120-column structured lines.
- AGENTS.md comments rule now prefers structure over a long prose paragraph.
Scope docs to C# and Actions, dropping shared-template carryover:
- Remove the Python section and the multi-language / derived-repo framing
from CODESTYLE.md; de-template .editorconfig, copilot-instructions.md, and
.vscode/tasks.json.
- Prune orphaned Python-tooling words from cspell.json.
tasks.json: add "Run Codegen" and "Codegen and Format" (codegen then
CSharpier, since generated line lengths are not always CSharpier-aligned).
README contributing/setup now point to WORKFLOW.md, CODESTYLE.md, and
repo-config (maintainer edit).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 27, 2026 22:57

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 27 out of 27 changed files in this pull request and generated 2 comments.

Comment threadWORKFLOW.md Outdated
Comment threadcspell.json Outdated
- Reconcile the Dependabot/fork validation contract: there is no pull_request
trigger, so Dependabot PRs (in-repo branches) validate via their push, and
only forks (which cannot push) need maintainer action. Previously the doc
claimed a base-resolved pull_request fallback that does not exist.
- cspell: set language to en-US to match the documented US-English rule.
- Remove the temporary go-live adoption note.
- Drop the project-type generality section and the multi-shape / portability
framing, scoping the spec to this NuGet library's workflows.
- Fix a broken concurrency sentence and clause-joining semicolons.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 27 out of 27 changed files in this pull request and generated 2 comments.

Comment thread.github/workflows/build-release-task.yml
Comment threadrepo-config/configure.sh
ptr727and others added 2 commits June 27, 2026 16:19
check_secrets now passes --paginate to the actions/secrets and
dependabot/secrets endpoints, so a repo with more than 30 secrets cannot miss
a required name and report a false failure.
The NuGet/login output finding is a false positive: the pinned
NuGet/login@v1.2.0 action.yml outputs NUGET_API_KEY, which the push step uses.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Tighten the verbose narrative in sections 0 and 3 and the longest guarantees
(D4.6, D8.3), drop redundant re-explanation, and remove clause-joining
semicolons. All guarantees (D0-D10) and scenarios (S1-S15) are preserved.
Also fix a model-paragraph inconsistency: it listed a runtime-dependency
update as auto-publishing, but dependency bumps are excluded from the
shipped-input inclusion list. The package publishes on a shipped-input change.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 27, 2026 23:28

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 27 out of 27 changed files in this pull request and generated 4 comments.

Comment thread.github/workflows/test-pull-request.yml
Comment threadrepo-config/configure.sh Outdated
Comment threadrepo-config/README.md
Comment threadrepo-config/README.md Outdated
- test-pull-request: restrict the push trigger to branches ['**'] so release
tags never re-run CI (the contract is CI for every branch, not tags).
- configure.sh and repo-config README: both check and apply use admin-only
rulesets/secrets endpoints, so check needs an admin-authenticated gh token
too (read-only, but not the default CI token). Corrected the misleading
"safe for CI" wording.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@ptr727
ptr727 merged commit b945a2b into developJun 28, 2026
10 checks passed
@ptr727
ptr727 deleted the feature/branch-scoped-cicd branch June 28, 2026 00:18
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Revert to branch-scoped self-publishing CI/CD - #204

Merged
ptr727 merged 9 commits into
developfrom
feature/branch-scoped-cicd
Jun 28, 2026
Merged

Revert to branch-scoped self-publishing CI/CD#204
ptr727 merged 9 commits into
developfrom
feature/branch-scoped-cicd

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Summary

Replaces the shared project-template CI/CD with a branch-scoped, self-sufficient workflow set written for this repo. One run targets the branch it was triggered on; NBGV versions it natively; a reusable validate-task (unit tests + lint) gates both the pull request and the publisher; and a shipped-input push to main/develop self-publishes (main stable, develop prerelease) with no schedule or PUBLISH_ON_MERGE.

Changes

  • WORKFLOW.md - canonical branch-scoped CI/CD spec + audit methodology (5A static / 5B trace / 5C live / 5D config).
  • validate-task.yml - unit-test + lint (csharpier, dotnet format, markdownlint, cspell, actionlint); the PR gate and the publish job both need: it, so nothing publishes that would fail the PR.
  • Rewrote publish-release / test-pull-request / build-release-task; deleted get-version / build-nugetlibrary / build-datebadge.
  • NuGet publishing is keyless via OIDC trusted publishing (NUGET_USERNAME, no API key).
  • repo-config/ - rulesets, settings, and configure.sh apply|check (the 5D config audit).
  • cspell.json - single-source spell dictionary (extension + CLI + CI read it).
  • Reconciled AGENTS.md / CODESTYLE.md / README.md / HISTORY.md; bumped to 1.5.

Go-live coordination (maintainer)

  • The aggregator required check is renamed to Check pull request workflow status job. The live ruleset still requires the old name, so repo-config/configure.sh apply must run in lockstep with merging this PR (it also fixes delete_branch_on_merge). Until then the live required check is satisfied by the base-resolved old workflow.
  • version.json is bumped (1.4 -> 1.5), a shipped input, so merging this to develop will auto-publish a 1.5 prerelease to NuGet. Intended, but flagging it.

🤖 Generated with Claude Code

Replace the shared project-template workflow model with a branch-scoped,
self-sufficient set written for this repo. One run targets the branch it was
triggered on; NBGV versions it natively (no IGNORE_GITHUB_REF / checkout -B);
a reusable validate-task (unit tests + lint) gates both the pull request and
the publisher; and a shipped-input push to main/develop self-publishes (main
stable, develop prerelease) with no schedule or PUBLISH_ON_MERGE.
- Add WORKFLOW.md: canonical branch-scoped CI/CD spec plus audit methodology.
- Add validate-task.yml (unit-test plus lint: csharpier, dotnet format,
markdownlint, cspell, actionlint); PR gate and publish job both need it.
- Rewrite publish-release/test-pull-request/build-release-task; delete the
get-version/build-nugetlibrary/build-datebadge tasks.
- NuGet publishing is keyless via OIDC trusted publishing (NUGET_USERNAME, no
long-lived API key).
- Add repo-config/ (rulesets, settings, configure.sh apply|check 5D audit) and
cspell.json (single-source spell dictionary).
- Reconcile AGENTS.md/CODESTYLE.md/README.md/HISTORY.md; bump version to 1.5.
Rename the required status check to "Check pull request workflow status job";
the live ruleset must be applied in lockstep (repo-config/configure.sh apply).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 27, 2026 21:21

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR replaces the template-derived, matrix/scheduled CI/CD with a repo-specific, branch-scoped workflow set where each run targets only the triggering branch (main = stable, develop = prerelease), reusing a single validate-task gate for both PR validation and publishing. It also codifies repo settings/rulesets/secrets-as-names under repo-config/ and updates docs/versioning to reflect the new operational contract.

Changes:

  • Added a canonical CI/CD contract + audit methodology (WORKFLOW.md) and a config-as-code audit/apply toolchain (repo-config/).
  • Introduced validate-task.yml (unit test + lint suite) and rewired test-pull-request.yml / publish-release.yml / build-release-task.yml around branch-scoped self-publishing + OIDC NuGet trusted publishing.
  • Updated release/docs metadata (bump version.json to 1.5; refreshed README.md, HISTORY.md, AGENTS.md, CODESTYLE.md; centralized spelling words in cspell.json and removed workspace-local dictionary).

Reviewed changes

Copilot reviewed 23 out of 23 changed files in this pull request and generated 5 comments.

Show a summary per file
FileDescription
WORKFLOW.mdNew end-to-end CI/CD contract (architecture, guarantees, and audit methodology).
version.jsonBumps version floor from 1.4 to 1.5.
repo-config/settings.jsonDeclares desired repository settings (auto-merge, merge methods, delete-branch-on-merge).
repo-config/ruleset-main.jsonCodifies main ruleset (merge-commit only, required check, signatures, strict off).
repo-config/ruleset-develop.jsonCodifies develop ruleset (squash-only + linear history, required check, signatures, strict off).
repo-config/README.mdDocuments config-as-code scope and the required-check rename lockstep.
repo-config/configure.shAdds `apply
README.mdUpdates release notes, CI/CD description, required-check name, and publishing/auth model.
HISTORY.mdAdds 1.5 entry describing CI/CD revert/rework and keyless publishing.
LanguageTags.code-workspaceRemoves embedded cSpell word list (now centralized in cspell.json).
cspell.jsonNew single-source spell dictionary + ignore paths.
CODESTYLE.mdUpdates clean-compile/lint/spell guidance to match CI + cspell.json.
AGENTS.mdRe-points CI/CD canon to WORKFLOW.md and updates merge/release semantics accordingly.
.github/workflows/validate-task.ymlNew reusable validation gate (unit tests + CSharpier/dotnet-format/markdownlint/cspell/actionlint).
.github/workflows/test-pull-request.ymlReworked CI entry workflow to run on push + produce the ruleset-bound aggregator check.
.github/workflows/publish-release.ymlReworked publisher to be branch-scoped + shipped-input path gated; uses validate-task gate.
.github/workflows/build-release-task.ymlReworked build/version/publish/release reusable task; adds OIDC NuGet trusted publishing and simplified asset handling.
.github/workflows/run-periodic-codegen-pull-request.ymlUpdates description/comments; maintains scheduled daily codegen entry workflow.
.github/workflows/run-codegen-pull-request-task.ymlUpdates documentation/comments around per-branch codegen PR creation.
.github/workflows/merge-bot-pull-request.ymlRemoves semver-major NuGet exception; makes Dependabot auto-merge unconditional on green checks.
.github/workflows/get-version-task.ymlDeleted (versioning now handled inside build-release-task.yml).
.github/workflows/build-nugetlibrary-task.ymlDeleted (logic folded into build-release-task.yml).
.github/workflows/build-datebadge-task.ymlDeleted (BYOB date badge removed).

Comment threadWORKFLOW.md Outdated
Comment threadWORKFLOW.md Outdated
Comment thread.github/workflows/build-release-task.yml Outdated
Comment thread.github/workflows/validate-task.yml Outdated
Comment thread.github/workflows/test-pull-request.yml Outdated
ptr727and others added 2 commits June 27, 2026 14:26
The project sets GeneratePackageOnBuild, so the build emits the .nupkg
(+ .snupkg). Running dotnet pack on top of that double-packs and fails to
find the assembly under the .artifacts layout ("LanguageTags.dll to be
packed was not found"). Build instead, redirecting OutputPath and
PackageOutputPath out of .artifacts, matching the prior working task.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…ctionlint
- WORKFLOW.md: frame dependency-bump exclusion as a deliberate churn-avoidance
policy, not a "no compiled code change" technical invariant (x2).
- build-release-task: correct the smoke validate-release skip rationale; smoke
can run on main, so the reason is "smoke never publishes", not "never main".
- validate-task: verify the actionlint release tarball against its published
SHA-256 before extracting/executing it, closing the unchecked-download path.
- test-pull-request: make the no-pull_request-trigger fork constraint and the
maintainer workflow explicit in the header.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 27, 2026 21:31

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 23 out of 23 changed files in this pull request and generated 2 comments.

Comment thread.github/workflows/build-release-task.yml
Comment threadREADME.md Outdated
ptr727and others added 2 commits June 27, 2026 14:39
… action
- Replace Unicode arrows (->) and an ellipsis (...) in README.md and the
dependabot.yml comments with ASCII, per AGENTS.md "no Unicode arrows / no
ellipsis character".
- Lint workflows via the SHA-pinned raven-actions/actionlint action (vendors
actionlint + shellcheck) instead of a hand-rolled curl download, matching
the repo's pin-every-action convention and dropping manual checksum upkeep.
The snupkg comment is a false positive: dotnet nuget push auto-pushes the
co-located .snupkg to nuget.org (no --no-symbols), as the workflow documents.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Comments:
- Trim verbose workflow comments to the non-obvious points. Move the snupkg
note onto the push step, name GitCommitId where comments said "built
commit", and make the artifact-delete gate explicit.
- Restructure publish-release's top comment into bullets, and drop prose
semicolons and inline spec-section refs (D4.6 etc.) across the workflows.
- Reflow dependabot.yml comments to ~120-column structured lines.
- AGENTS.md comments rule now prefers structure over a long prose paragraph.
Scope docs to C# and Actions, dropping shared-template carryover:
- Remove the Python section and the multi-language / derived-repo framing
from CODESTYLE.md; de-template .editorconfig, copilot-instructions.md, and
.vscode/tasks.json.
- Prune orphaned Python-tooling words from cspell.json.
tasks.json: add "Run Codegen" and "Codegen and Format" (codegen then
CSharpier, since generated line lengths are not always CSharpier-aligned).
README contributing/setup now point to WORKFLOW.md, CODESTYLE.md, and
repo-config (maintainer edit).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 27, 2026 22:57

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 27 out of 27 changed files in this pull request and generated 2 comments.

Comment threadWORKFLOW.md Outdated
Comment threadcspell.json Outdated
- Reconcile the Dependabot/fork validation contract: there is no pull_request
trigger, so Dependabot PRs (in-repo branches) validate via their push, and
only forks (which cannot push) need maintainer action. Previously the doc
claimed a base-resolved pull_request fallback that does not exist.
- cspell: set language to en-US to match the documented US-English rule.
- Remove the temporary go-live adoption note.
- Drop the project-type generality section and the multi-shape / portability
framing, scoping the spec to this NuGet library's workflows.
- Fix a broken concurrency sentence and clause-joining semicolons.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 27 out of 27 changed files in this pull request and generated 2 comments.

Comment thread.github/workflows/build-release-task.yml
Comment threadrepo-config/configure.sh
ptr727and others added 2 commits June 27, 2026 16:19
check_secrets now passes --paginate to the actions/secrets and
dependabot/secrets endpoints, so a repo with more than 30 secrets cannot miss
a required name and report a false failure.
The NuGet/login output finding is a false positive: the pinned
NuGet/login@v1.2.0 action.yml outputs NUGET_API_KEY, which the push step uses.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Tighten the verbose narrative in sections 0 and 3 and the longest guarantees
(D4.6, D8.3), drop redundant re-explanation, and remove clause-joining
semicolons. All guarantees (D0-D10) and scenarios (S1-S15) are preserved.
Also fix a model-paragraph inconsistency: it listed a runtime-dependency
update as auto-publishing, but dependency bumps are excluded from the
shipped-input inclusion list. The package publishes on a shipped-input change.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 27, 2026 23:28

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 27 out of 27 changed files in this pull request and generated 4 comments.

Comment thread.github/workflows/test-pull-request.yml
Comment threadrepo-config/configure.sh Outdated
Comment threadrepo-config/README.md
Comment threadrepo-config/README.md Outdated
- test-pull-request: restrict the push trigger to branches ['**'] so release
tags never re-run CI (the contract is CI for every branch, not tags).
- configure.sh and repo-config README: both check and apply use admin-only
rulesets/secrets endpoints, so check needs an admin-authenticated gh token
too (read-only, but not the default CI token). Corrected the misleading
"safe for CI" wording.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@ptr727
ptr727 merged commit b945a2b into developJun 28, 2026
10 checks passed
@ptr727
ptr727 deleted the feature/branch-scoped-cicd branch June 28, 2026 00:18
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727