Skip to content

Republish on dependency bumps; harden configure.sh - #211

Merged
ptr727 merged 4 commits into
developfrom
feature/publish-dep-currency
Jun 29, 2026
Merged

Republish on dependency bumps; harden configure.sh#211
ptr727 merged 4 commits into
developfrom
feature/publish-dep-currency

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Keeps the push-self-publish model (correct for NuGet - there is no Docker-style refresh, and a NuGet version can't be re-pushed) and closes the stale-dependency window, plus brings repo-config in line with the hardened canonical.

Dependency currency

A NuGet package's declared dependencies only update when a new version is published. With no scheduled rebuild possible, a merged dependency bump must republish or the package keeps shipping old/vulnerable dependency constraints. So Directory.Packages.props is now a shipped input: a dependency bump on main/develop auto-publishes that branch, keeping the package current. GitHub-Actions bumps stay excluded (they do not ship in the package).

Trade-off (accepted): because versions are centrally managed, a test/codegen dependency bump (e.g. xunit.v3) also republishes even though it does not ship - cheap version churn in exchange for never shipping a stale dependency. (The shipped library has effectively one runtime dependency, Microsoft.Extensions.Logging.Abstractions.)

WORKFLOW.md (glossary, D4.1, D8.2, 5A audit, S11) and AGENTS.md updated to match.

repo-config hardening

configure.shruleset_id distinguishes an absent ruleset from a real API error (lets gh surface its stderr; returns non-zero instead of a silent set -e abort), uses jq --arg, selects the first match inside jq (pipefail-safe), and pages the lookup (per_page=100). The repo-config README states the actual branch cleanup (auto-delete off so a develop -> main promotion does not delete develop; merged bot/feature branches cleaned up manually). Task comments aligned to the terse canonical form.

Verification

actionlint, markdownlint, shellcheck, bash -n clean; EOL preserved.

ptr727and others added 2 commits June 28, 2026 17:43
Bring repo-config in line with the hardened canonical: ruleset_id distinguishes an absent
ruleset from a real API error (lets gh surface its own stderr, returns non-zero instead of
a silent set -e abort), uses jq --arg, selects the first match inside jq (pipefail-safe),
and pages the lookup (per_page=100). The repo-config README states the actual branch
cleanup (auto-delete off so a develop -> main promotion does not delete develop; merged
bot/feature branches are cleaned up manually). Also aligns the validate/test-pr task
comments to the terse canonical form.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Add Directory.Packages.props to the publisher's shipped-input paths. A NuGet version
cannot be re-pushed, so (unlike a Docker image with a weekly base refresh) the only way the
published package's declared dependencies get a security/patch update is to republish when
a dependency bumps. GitHub-Actions bumps stay excluded - they do not ship in the package.
Update WORKFLOW.md (glossary, D4.1, D8.2, 5A audit, S11) and AGENTS.md to match.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 29, 2026 00:44

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the repo’s CI/publish contract so dependency bumps trigger a republish (to keep NuGet dependency constraints current), and hardens the repo-config configuration script for more reliable auditing/apply behavior.

Changes:

  • Treat Directory.Packages.props as a shipped input so merges that bump dependencies auto-publish on main/develop.
  • Harden repo-config/configure.sh (ruleset lookup paging/error behavior, jq safety, explicit “no linear history” assertion for main, improved secrets audit behavior).
  • Adjust CI workflows: skip jobs on branch-deletion push events; simplify workflow lint step configuration.

Reviewed changes

Copilot reviewed 7 out of 7 changed files in this pull request and generated 3 comments.

Show a summary per file
FileDescription
WORKFLOW.mdDocuments dependency-bump republish behavior and updates the shipped-input inclusion list.
AGENTS.mdUpdates the “merging releases” guidance to include dependency bumps as shipped inputs.
.github/workflows/publish-release.ymlAdds Directory.Packages.props to the publish on.push.paths inclusion list.
.github/workflows/test-pull-request.ymlSkips CI jobs on branch-deletion push events to avoid all-zero SHA failures.
.github/workflows/validate-task.ymlSimplifies the actionlint step configuration.
repo-config/configure.shHardens repo configuration auditing/apply logic and adds jq_lacks.
repo-config/README.mdClarifies branch auto-delete behavior and cleanup expectations.

Comment threadrepo-config/configure.sh Outdated
Comment threadrepo-config/configure.sh Outdated
Comment threadrepo-config/configure.sh Outdated
jq_lacks now propagates a real jq error (exit >1) instead of treating it as "lacks", so a
malformed filter/input fails the assert loudly rather than passing. check_secrets stops
suppressing gh's stderr (so the API/auth failure cause is visible, like ruleset_id) and its
comment matches the actual fail-fast behavior.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comment threadrepo-config/README.md Outdated
This repo's merge-bot merges with `gh pr merge --delete-branch`, so merged bot branches ARE
deleted (verified: no leftover dependabot/* branches). Distinguish the repo-wide auto-delete
setting (off, so a develop -> main promotion does not delete develop) from the explicit
per-merge deletion the merge-bot/maintainer performs.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated no new comments.

@ptr727
ptr727 merged commit 8b3a0cf into developJun 29, 2026
11 checks passed
@ptr727
ptr727 deleted the feature/publish-dep-currency branch June 29, 2026 00:57
ptr727 added a commit that referenced this pull request Jun 29, 2026
Capture jq's exit code with `|| rc=$?` (a list is exempt from errexit)
so an exit-1 no-match returns 'lacks' rather than risking a `set -e`
abort outside a conditional, while still propagating a real jq error
(>1). Verified under `set -euo pipefail` for match / no-match /
jq-error. Follow-up to PR #211.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
ptr727 added a commit that referenced this pull request Jun 29, 2026
Narrow the publish-release header comment - a package-version
(Directory.Packages.props) bump republishes; only a GitHub-Actions
Dependabot bump does not. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
ptr727 added a commit that referenced this pull request Jun 29, 2026
WORKFLOW.md said validate/smoke-build run unconditionally, but they
carry a `!github.event.deleted` guard. Note the branch-deletion
exception in the architecture section, D1.1, and the 5A audit, and add
scenario S16. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
ptr727 added a commit that referenced this pull request Jun 29, 2026
checkout/build fail -> fails. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
ptr727 added a commit that referenced this pull request Jun 29, 2026
Section 0's model-at-a-glance omitted package versions from the
shipped-input list (the glossary/D4.1 include them). Add it. Follow-up
to #211/#212.
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
ptr727 added a commit that referenced this pull request Jun 29, 2026
The on.push.paths inclusion list is below the header comment; change
'add a path above' to 'add a path to that list'. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Republish on dependency bumps; harden configure.sh by ptr727 · Pull Request #211 · ptr727/LanguageTags · GitHub
Skip to content

Republish on dependency bumps; harden configure.sh - #211

Merged
ptr727 merged 4 commits into
developfrom
feature/publish-dep-currency
Jun 29, 2026
Merged

Republish on dependency bumps; harden configure.sh#211
ptr727 merged 4 commits into
developfrom
feature/publish-dep-currency

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Keeps the push-self-publish model (correct for NuGet - there is no Docker-style refresh, and a NuGet version can't be re-pushed) and closes the stale-dependency window, plus brings repo-config in line with the hardened canonical.

Dependency currency

A NuGet package's declared dependencies only update when a new version is published. With no scheduled rebuild possible, a merged dependency bump must republish or the package keeps shipping old/vulnerable dependency constraints. So Directory.Packages.props is now a shipped input: a dependency bump on main/develop auto-publishes that branch, keeping the package current. GitHub-Actions bumps stay excluded (they do not ship in the package).

Trade-off (accepted): because versions are centrally managed, a test/codegen dependency bump (e.g. xunit.v3) also republishes even though it does not ship - cheap version churn in exchange for never shipping a stale dependency. (The shipped library has effectively one runtime dependency, Microsoft.Extensions.Logging.Abstractions.)

WORKFLOW.md (glossary, D4.1, D8.2, 5A audit, S11) and AGENTS.md updated to match.

repo-config hardening

configure.shruleset_id distinguishes an absent ruleset from a real API error (lets gh surface its stderr; returns non-zero instead of a silent set -e abort), uses jq --arg, selects the first match inside jq (pipefail-safe), and pages the lookup (per_page=100). The repo-config README states the actual branch cleanup (auto-delete off so a develop -> main promotion does not delete develop; merged bot/feature branches cleaned up manually). Task comments aligned to the terse canonical form.

Verification

actionlint, markdownlint, shellcheck, bash -n clean; EOL preserved.

ptr727and others added 2 commits June 28, 2026 17:43
Bring repo-config in line with the hardened canonical: ruleset_id distinguishes an absent
ruleset from a real API error (lets gh surface its own stderr, returns non-zero instead of
a silent set -e abort), uses jq --arg, selects the first match inside jq (pipefail-safe),
and pages the lookup (per_page=100). The repo-config README states the actual branch
cleanup (auto-delete off so a develop -> main promotion does not delete develop; merged
bot/feature branches are cleaned up manually). Also aligns the validate/test-pr task
comments to the terse canonical form.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Add Directory.Packages.props to the publisher's shipped-input paths. A NuGet version
cannot be re-pushed, so (unlike a Docker image with a weekly base refresh) the only way the
published package's declared dependencies get a security/patch update is to republish when
a dependency bumps. GitHub-Actions bumps stay excluded - they do not ship in the package.
Update WORKFLOW.md (glossary, D4.1, D8.2, 5A audit, S11) and AGENTS.md to match.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 29, 2026 00:44

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the repo’s CI/publish contract so dependency bumps trigger a republish (to keep NuGet dependency constraints current), and hardens the repo-config configuration script for more reliable auditing/apply behavior.

Changes:

  • Treat Directory.Packages.props as a shipped input so merges that bump dependencies auto-publish on main/develop.
  • Harden repo-config/configure.sh (ruleset lookup paging/error behavior, jq safety, explicit “no linear history” assertion for main, improved secrets audit behavior).
  • Adjust CI workflows: skip jobs on branch-deletion push events; simplify workflow lint step configuration.

Reviewed changes

Copilot reviewed 7 out of 7 changed files in this pull request and generated 3 comments.

Show a summary per file
FileDescription
WORKFLOW.mdDocuments dependency-bump republish behavior and updates the shipped-input inclusion list.
AGENTS.mdUpdates the “merging releases” guidance to include dependency bumps as shipped inputs.
.github/workflows/publish-release.ymlAdds Directory.Packages.props to the publish on.push.paths inclusion list.
.github/workflows/test-pull-request.ymlSkips CI jobs on branch-deletion push events to avoid all-zero SHA failures.
.github/workflows/validate-task.ymlSimplifies the actionlint step configuration.
repo-config/configure.shHardens repo configuration auditing/apply logic and adds jq_lacks.
repo-config/README.mdClarifies branch auto-delete behavior and cleanup expectations.

Comment threadrepo-config/configure.sh Outdated
Comment threadrepo-config/configure.sh Outdated
Comment threadrepo-config/configure.sh Outdated
jq_lacks now propagates a real jq error (exit >1) instead of treating it as "lacks", so a
malformed filter/input fails the assert loudly rather than passing. check_secrets stops
suppressing gh's stderr (so the API/auth failure cause is visible, like ruleset_id) and its
comment matches the actual fail-fast behavior.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comment threadrepo-config/README.md Outdated
This repo's merge-bot merges with `gh pr merge --delete-branch`, so merged bot branches ARE
deleted (verified: no leftover dependabot/* branches). Distinguish the repo-wide auto-delete
setting (off, so a develop -> main promotion does not delete develop) from the explicit
per-merge deletion the merge-bot/maintainer performs.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated no new comments.

@ptr727
ptr727 merged commit 8b3a0cf into developJun 29, 2026
11 checks passed
@ptr727
ptr727 deleted the feature/publish-dep-currency branch June 29, 2026 00:57
ptr727 added a commit that referenced this pull request Jun 29, 2026
Capture jq's exit code with `|| rc=$?` (a list is exempt from errexit)
so an exit-1 no-match returns 'lacks' rather than risking a `set -e`
abort outside a conditional, while still propagating a real jq error
(>1). Verified under `set -euo pipefail` for match / no-match /
jq-error. Follow-up to PR #211.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
ptr727 added a commit that referenced this pull request Jun 29, 2026
Narrow the publish-release header comment - a package-version
(Directory.Packages.props) bump republishes; only a GitHub-Actions
Dependabot bump does not. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
ptr727 added a commit that referenced this pull request Jun 29, 2026
WORKFLOW.md said validate/smoke-build run unconditionally, but they
carry a `!github.event.deleted` guard. Note the branch-deletion
exception in the architecture section, D1.1, and the 5A audit, and add
scenario S16. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
ptr727 added a commit that referenced this pull request Jun 29, 2026
checkout/build fail -> fails. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
ptr727 added a commit that referenced this pull request Jun 29, 2026
Section 0's model-at-a-glance omitted package versions from the
shipped-input list (the glossary/D4.1 include them). Add it. Follow-up
to #211/#212.
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
ptr727 added a commit that referenced this pull request Jun 29, 2026
The on.push.paths inclusion list is below the header comment; change
'add a path above' to 'add a path to that list'. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Republish on dependency bumps; harden configure.sh by ptr727 · Pull Request #211 · ptr727/LanguageTags · GitHub
Skip to content

Republish on dependency bumps; harden configure.sh - #211

Merged
ptr727 merged 4 commits into
developfrom
feature/publish-dep-currency
Jun 29, 2026
Merged

Republish on dependency bumps; harden configure.sh#211
ptr727 merged 4 commits into
developfrom
feature/publish-dep-currency

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Keeps the push-self-publish model (correct for NuGet - there is no Docker-style refresh, and a NuGet version can't be re-pushed) and closes the stale-dependency window, plus brings repo-config in line with the hardened canonical.

Dependency currency

A NuGet package's declared dependencies only update when a new version is published. With no scheduled rebuild possible, a merged dependency bump must republish or the package keeps shipping old/vulnerable dependency constraints. So Directory.Packages.props is now a shipped input: a dependency bump on main/develop auto-publishes that branch, keeping the package current. GitHub-Actions bumps stay excluded (they do not ship in the package).

Trade-off (accepted): because versions are centrally managed, a test/codegen dependency bump (e.g. xunit.v3) also republishes even though it does not ship - cheap version churn in exchange for never shipping a stale dependency. (The shipped library has effectively one runtime dependency, Microsoft.Extensions.Logging.Abstractions.)

WORKFLOW.md (glossary, D4.1, D8.2, 5A audit, S11) and AGENTS.md updated to match.

repo-config hardening

configure.shruleset_id distinguishes an absent ruleset from a real API error (lets gh surface its stderr; returns non-zero instead of a silent set -e abort), uses jq --arg, selects the first match inside jq (pipefail-safe), and pages the lookup (per_page=100). The repo-config README states the actual branch cleanup (auto-delete off so a develop -> main promotion does not delete develop; merged bot/feature branches cleaned up manually). Task comments aligned to the terse canonical form.

Verification

actionlint, markdownlint, shellcheck, bash -n clean; EOL preserved.

ptr727and others added 2 commits June 28, 2026 17:43
Bring repo-config in line with the hardened canonical: ruleset_id distinguishes an absent
ruleset from a real API error (lets gh surface its own stderr, returns non-zero instead of
a silent set -e abort), uses jq --arg, selects the first match inside jq (pipefail-safe),
and pages the lookup (per_page=100). The repo-config README states the actual branch
cleanup (auto-delete off so a develop -> main promotion does not delete develop; merged
bot/feature branches are cleaned up manually). Also aligns the validate/test-pr task
comments to the terse canonical form.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Add Directory.Packages.props to the publisher's shipped-input paths. A NuGet version
cannot be re-pushed, so (unlike a Docker image with a weekly base refresh) the only way the
published package's declared dependencies get a security/patch update is to republish when
a dependency bumps. GitHub-Actions bumps stay excluded - they do not ship in the package.
Update WORKFLOW.md (glossary, D4.1, D8.2, 5A audit, S11) and AGENTS.md to match.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 29, 2026 00:44

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the repo’s CI/publish contract so dependency bumps trigger a republish (to keep NuGet dependency constraints current), and hardens the repo-config configuration script for more reliable auditing/apply behavior.

Changes:

  • Treat Directory.Packages.props as a shipped input so merges that bump dependencies auto-publish on main/develop.
  • Harden repo-config/configure.sh (ruleset lookup paging/error behavior, jq safety, explicit “no linear history” assertion for main, improved secrets audit behavior).
  • Adjust CI workflows: skip jobs on branch-deletion push events; simplify workflow lint step configuration.

Reviewed changes

Copilot reviewed 7 out of 7 changed files in this pull request and generated 3 comments.

Show a summary per file
FileDescription
WORKFLOW.mdDocuments dependency-bump republish behavior and updates the shipped-input inclusion list.
AGENTS.mdUpdates the “merging releases” guidance to include dependency bumps as shipped inputs.
.github/workflows/publish-release.ymlAdds Directory.Packages.props to the publish on.push.paths inclusion list.
.github/workflows/test-pull-request.ymlSkips CI jobs on branch-deletion push events to avoid all-zero SHA failures.
.github/workflows/validate-task.ymlSimplifies the actionlint step configuration.
repo-config/configure.shHardens repo configuration auditing/apply logic and adds jq_lacks.
repo-config/README.mdClarifies branch auto-delete behavior and cleanup expectations.

Comment threadrepo-config/configure.sh Outdated
Comment threadrepo-config/configure.sh Outdated
Comment threadrepo-config/configure.sh Outdated
jq_lacks now propagates a real jq error (exit >1) instead of treating it as "lacks", so a
malformed filter/input fails the assert loudly rather than passing. check_secrets stops
suppressing gh's stderr (so the API/auth failure cause is visible, like ruleset_id) and its
comment matches the actual fail-fast behavior.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comment threadrepo-config/README.md Outdated
This repo's merge-bot merges with `gh pr merge --delete-branch`, so merged bot branches ARE
deleted (verified: no leftover dependabot/* branches). Distinguish the repo-wide auto-delete
setting (off, so a develop -> main promotion does not delete develop) from the explicit
per-merge deletion the merge-bot/maintainer performs.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated no new comments.

@ptr727
ptr727 merged commit 8b3a0cf into developJun 29, 2026
11 checks passed
@ptr727
ptr727 deleted the feature/publish-dep-currency branch June 29, 2026 00:57
ptr727 added a commit that referenced this pull request Jun 29, 2026
Capture jq's exit code with `|| rc=$?` (a list is exempt from errexit)
so an exit-1 no-match returns 'lacks' rather than risking a `set -e`
abort outside a conditional, while still propagating a real jq error
(>1). Verified under `set -euo pipefail` for match / no-match /
jq-error. Follow-up to PR #211.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
ptr727 added a commit that referenced this pull request Jun 29, 2026
Narrow the publish-release header comment - a package-version
(Directory.Packages.props) bump republishes; only a GitHub-Actions
Dependabot bump does not. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
ptr727 added a commit that referenced this pull request Jun 29, 2026
WORKFLOW.md said validate/smoke-build run unconditionally, but they
carry a `!github.event.deleted` guard. Note the branch-deletion
exception in the architecture section, D1.1, and the 5A audit, and add
scenario S16. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
ptr727 added a commit that referenced this pull request Jun 29, 2026
checkout/build fail -> fails. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
ptr727 added a commit that referenced this pull request Jun 29, 2026
Section 0's model-at-a-glance omitted package versions from the
shipped-input list (the glossary/D4.1 include them). Add it. Follow-up
to #211/#212.
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
ptr727 added a commit that referenced this pull request Jun 29, 2026
The on.push.paths inclusion list is below the header comment; change
'add a path above' to 'add a path to that list'. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Republish on dependency bumps; harden configure.sh by ptr727 · Pull Request #211 · ptr727/LanguageTags · GitHub
Skip to content

Republish on dependency bumps; harden configure.sh - #211

Merged
ptr727 merged 4 commits into
developfrom
feature/publish-dep-currency
Jun 29, 2026
Merged

Republish on dependency bumps; harden configure.sh#211
ptr727 merged 4 commits into
developfrom
feature/publish-dep-currency

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Keeps the push-self-publish model (correct for NuGet - there is no Docker-style refresh, and a NuGet version can't be re-pushed) and closes the stale-dependency window, plus brings repo-config in line with the hardened canonical.

Dependency currency

A NuGet package's declared dependencies only update when a new version is published. With no scheduled rebuild possible, a merged dependency bump must republish or the package keeps shipping old/vulnerable dependency constraints. So Directory.Packages.props is now a shipped input: a dependency bump on main/develop auto-publishes that branch, keeping the package current. GitHub-Actions bumps stay excluded (they do not ship in the package).

Trade-off (accepted): because versions are centrally managed, a test/codegen dependency bump (e.g. xunit.v3) also republishes even though it does not ship - cheap version churn in exchange for never shipping a stale dependency. (The shipped library has effectively one runtime dependency, Microsoft.Extensions.Logging.Abstractions.)

WORKFLOW.md (glossary, D4.1, D8.2, 5A audit, S11) and AGENTS.md updated to match.

repo-config hardening

configure.shruleset_id distinguishes an absent ruleset from a real API error (lets gh surface its stderr; returns non-zero instead of a silent set -e abort), uses jq --arg, selects the first match inside jq (pipefail-safe), and pages the lookup (per_page=100). The repo-config README states the actual branch cleanup (auto-delete off so a develop -> main promotion does not delete develop; merged bot/feature branches cleaned up manually). Task comments aligned to the terse canonical form.

Verification

actionlint, markdownlint, shellcheck, bash -n clean; EOL preserved.

ptr727and others added 2 commits June 28, 2026 17:43
Bring repo-config in line with the hardened canonical: ruleset_id distinguishes an absent
ruleset from a real API error (lets gh surface its own stderr, returns non-zero instead of
a silent set -e abort), uses jq --arg, selects the first match inside jq (pipefail-safe),
and pages the lookup (per_page=100). The repo-config README states the actual branch
cleanup (auto-delete off so a develop -> main promotion does not delete develop; merged
bot/feature branches are cleaned up manually). Also aligns the validate/test-pr task
comments to the terse canonical form.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Add Directory.Packages.props to the publisher's shipped-input paths. A NuGet version
cannot be re-pushed, so (unlike a Docker image with a weekly base refresh) the only way the
published package's declared dependencies get a security/patch update is to republish when
a dependency bumps. GitHub-Actions bumps stay excluded - they do not ship in the package.
Update WORKFLOW.md (glossary, D4.1, D8.2, 5A audit, S11) and AGENTS.md to match.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 29, 2026 00:44

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the repo’s CI/publish contract so dependency bumps trigger a republish (to keep NuGet dependency constraints current), and hardens the repo-config configuration script for more reliable auditing/apply behavior.

Changes:

  • Treat Directory.Packages.props as a shipped input so merges that bump dependencies auto-publish on main/develop.
  • Harden repo-config/configure.sh (ruleset lookup paging/error behavior, jq safety, explicit “no linear history” assertion for main, improved secrets audit behavior).
  • Adjust CI workflows: skip jobs on branch-deletion push events; simplify workflow lint step configuration.

Reviewed changes

Copilot reviewed 7 out of 7 changed files in this pull request and generated 3 comments.

Show a summary per file
FileDescription
WORKFLOW.mdDocuments dependency-bump republish behavior and updates the shipped-input inclusion list.
AGENTS.mdUpdates the “merging releases” guidance to include dependency bumps as shipped inputs.
.github/workflows/publish-release.ymlAdds Directory.Packages.props to the publish on.push.paths inclusion list.
.github/workflows/test-pull-request.ymlSkips CI jobs on branch-deletion push events to avoid all-zero SHA failures.
.github/workflows/validate-task.ymlSimplifies the actionlint step configuration.
repo-config/configure.shHardens repo configuration auditing/apply logic and adds jq_lacks.
repo-config/README.mdClarifies branch auto-delete behavior and cleanup expectations.

Comment threadrepo-config/configure.sh Outdated
Comment threadrepo-config/configure.sh Outdated
Comment threadrepo-config/configure.sh Outdated
jq_lacks now propagates a real jq error (exit >1) instead of treating it as "lacks", so a
malformed filter/input fails the assert loudly rather than passing. check_secrets stops
suppressing gh's stderr (so the API/auth failure cause is visible, like ruleset_id) and its
comment matches the actual fail-fast behavior.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comment threadrepo-config/README.md Outdated
This repo's merge-bot merges with `gh pr merge --delete-branch`, so merged bot branches ARE
deleted (verified: no leftover dependabot/* branches). Distinguish the repo-wide auto-delete
setting (off, so a develop -> main promotion does not delete develop) from the explicit
per-merge deletion the merge-bot/maintainer performs.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated no new comments.

@ptr727
ptr727 merged commit 8b3a0cf into developJun 29, 2026
11 checks passed
@ptr727
ptr727 deleted the feature/publish-dep-currency branch June 29, 2026 00:57
ptr727 added a commit that referenced this pull request Jun 29, 2026
Capture jq's exit code with `|| rc=$?` (a list is exempt from errexit)
so an exit-1 no-match returns 'lacks' rather than risking a `set -e`
abort outside a conditional, while still propagating a real jq error
(>1). Verified under `set -euo pipefail` for match / no-match /
jq-error. Follow-up to PR #211.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
ptr727 added a commit that referenced this pull request Jun 29, 2026
Narrow the publish-release header comment - a package-version
(Directory.Packages.props) bump republishes; only a GitHub-Actions
Dependabot bump does not. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
ptr727 added a commit that referenced this pull request Jun 29, 2026
WORKFLOW.md said validate/smoke-build run unconditionally, but they
carry a `!github.event.deleted` guard. Note the branch-deletion
exception in the architecture section, D1.1, and the 5A audit, and add
scenario S16. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
ptr727 added a commit that referenced this pull request Jun 29, 2026
checkout/build fail -> fails. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
ptr727 added a commit that referenced this pull request Jun 29, 2026
Section 0's model-at-a-glance omitted package versions from the
shipped-input list (the glossary/D4.1 include them). Add it. Follow-up
to #211/#212.
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
ptr727 added a commit that referenced this pull request Jun 29, 2026
The on.push.paths inclusion list is below the header comment; change
'add a path above' to 'add a path to that list'. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' Republish on dependency bumps; harden configure.sh by ptr727 · Pull Request #211 · ptr727/LanguageTags · GitHub
Skip to content

Republish on dependency bumps; harden configure.sh - #211

Merged
ptr727 merged 4 commits into
developfrom
feature/publish-dep-currency
Jun 29, 2026
Merged

Republish on dependency bumps; harden configure.sh#211
ptr727 merged 4 commits into
developfrom
feature/publish-dep-currency

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Keeps the push-self-publish model (correct for NuGet - there is no Docker-style refresh, and a NuGet version can't be re-pushed) and closes the stale-dependency window, plus brings repo-config in line with the hardened canonical.

Dependency currency

A NuGet package's declared dependencies only update when a new version is published. With no scheduled rebuild possible, a merged dependency bump must republish or the package keeps shipping old/vulnerable dependency constraints. So Directory.Packages.props is now a shipped input: a dependency bump on main/develop auto-publishes that branch, keeping the package current. GitHub-Actions bumps stay excluded (they do not ship in the package).

Trade-off (accepted): because versions are centrally managed, a test/codegen dependency bump (e.g. xunit.v3) also republishes even though it does not ship - cheap version churn in exchange for never shipping a stale dependency. (The shipped library has effectively one runtime dependency, Microsoft.Extensions.Logging.Abstractions.)

WORKFLOW.md (glossary, D4.1, D8.2, 5A audit, S11) and AGENTS.md updated to match.

repo-config hardening

configure.shruleset_id distinguishes an absent ruleset from a real API error (lets gh surface its stderr; returns non-zero instead of a silent set -e abort), uses jq --arg, selects the first match inside jq (pipefail-safe), and pages the lookup (per_page=100). The repo-config README states the actual branch cleanup (auto-delete off so a develop -> main promotion does not delete develop; merged bot/feature branches cleaned up manually). Task comments aligned to the terse canonical form.

Verification

actionlint, markdownlint, shellcheck, bash -n clean; EOL preserved.

ptr727and others added 2 commits June 28, 2026 17:43
Bring repo-config in line with the hardened canonical: ruleset_id distinguishes an absent
ruleset from a real API error (lets gh surface its own stderr, returns non-zero instead of
a silent set -e abort), uses jq --arg, selects the first match inside jq (pipefail-safe),
and pages the lookup (per_page=100). The repo-config README states the actual branch
cleanup (auto-delete off so a develop -> main promotion does not delete develop; merged
bot/feature branches are cleaned up manually). Also aligns the validate/test-pr task
comments to the terse canonical form.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Add Directory.Packages.props to the publisher's shipped-input paths. A NuGet version
cannot be re-pushed, so (unlike a Docker image with a weekly base refresh) the only way the
published package's declared dependencies get a security/patch update is to republish when
a dependency bumps. GitHub-Actions bumps stay excluded - they do not ship in the package.
Update WORKFLOW.md (glossary, D4.1, D8.2, 5A audit, S11) and AGENTS.md to match.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 29, 2026 00:44

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the repo’s CI/publish contract so dependency bumps trigger a republish (to keep NuGet dependency constraints current), and hardens the repo-config configuration script for more reliable auditing/apply behavior.

Changes:

  • Treat Directory.Packages.props as a shipped input so merges that bump dependencies auto-publish on main/develop.
  • Harden repo-config/configure.sh (ruleset lookup paging/error behavior, jq safety, explicit “no linear history” assertion for main, improved secrets audit behavior).
  • Adjust CI workflows: skip jobs on branch-deletion push events; simplify workflow lint step configuration.

Reviewed changes

Copilot reviewed 7 out of 7 changed files in this pull request and generated 3 comments.

Show a summary per file
FileDescription
WORKFLOW.mdDocuments dependency-bump republish behavior and updates the shipped-input inclusion list.
AGENTS.mdUpdates the “merging releases” guidance to include dependency bumps as shipped inputs.
.github/workflows/publish-release.ymlAdds Directory.Packages.props to the publish on.push.paths inclusion list.
.github/workflows/test-pull-request.ymlSkips CI jobs on branch-deletion push events to avoid all-zero SHA failures.
.github/workflows/validate-task.ymlSimplifies the actionlint step configuration.
repo-config/configure.shHardens repo configuration auditing/apply logic and adds jq_lacks.
repo-config/README.mdClarifies branch auto-delete behavior and cleanup expectations.

Comment threadrepo-config/configure.sh Outdated
Comment threadrepo-config/configure.sh Outdated
Comment threadrepo-config/configure.sh Outdated
jq_lacks now propagates a real jq error (exit >1) instead of treating it as "lacks", so a
malformed filter/input fails the assert loudly rather than passing. check_secrets stops
suppressing gh's stderr (so the API/auth failure cause is visible, like ruleset_id) and its
comment matches the actual fail-fast behavior.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comment threadrepo-config/README.md Outdated
This repo's merge-bot merges with `gh pr merge --delete-branch`, so merged bot branches ARE
deleted (verified: no leftover dependabot/* branches). Distinguish the repo-wide auto-delete
setting (off, so a develop -> main promotion does not delete develop) from the explicit
per-merge deletion the merge-bot/maintainer performs.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated no new comments.

@ptr727
ptr727 merged commit 8b3a0cf into developJun 29, 2026
11 checks passed
@ptr727
ptr727 deleted the feature/publish-dep-currency branch June 29, 2026 00:57
ptr727 added a commit that referenced this pull request Jun 29, 2026
Capture jq's exit code with `|| rc=$?` (a list is exempt from errexit)
so an exit-1 no-match returns 'lacks' rather than risking a `set -e`
abort outside a conditional, while still propagating a real jq error
(>1). Verified under `set -euo pipefail` for match / no-match /
jq-error. Follow-up to PR #211.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
ptr727 added a commit that referenced this pull request Jun 29, 2026
Narrow the publish-release header comment - a package-version
(Directory.Packages.props) bump republishes; only a GitHub-Actions
Dependabot bump does not. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
ptr727 added a commit that referenced this pull request Jun 29, 2026
WORKFLOW.md said validate/smoke-build run unconditionally, but they
carry a `!github.event.deleted` guard. Note the branch-deletion
exception in the architecture section, D1.1, and the 5A audit, and add
scenario S16. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
ptr727 added a commit that referenced this pull request Jun 29, 2026
checkout/build fail -> fails. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
ptr727 added a commit that referenced this pull request Jun 29, 2026
Section 0's model-at-a-glance omitted package versions from the
shipped-input list (the glossary/D4.1 include them). Add it. Follow-up
to #211/#212.
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
ptr727 added a commit that referenced this pull request Jun 29, 2026
The on.push.paths inclusion list is below the header comment; change
'add a path above' to 'add a path to that list'. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Republish on dependency bumps; harden configure.sh by ptr727 · Pull Request #211 · ptr727/LanguageTags · GitHub
Skip to content

Republish on dependency bumps; harden configure.sh - #211

Merged
ptr727 merged 4 commits into
developfrom
feature/publish-dep-currency
Jun 29, 2026
Merged

Republish on dependency bumps; harden configure.sh#211
ptr727 merged 4 commits into
developfrom
feature/publish-dep-currency

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Keeps the push-self-publish model (correct for NuGet - there is no Docker-style refresh, and a NuGet version can't be re-pushed) and closes the stale-dependency window, plus brings repo-config in line with the hardened canonical.

Dependency currency

A NuGet package's declared dependencies only update when a new version is published. With no scheduled rebuild possible, a merged dependency bump must republish or the package keeps shipping old/vulnerable dependency constraints. So Directory.Packages.props is now a shipped input: a dependency bump on main/develop auto-publishes that branch, keeping the package current. GitHub-Actions bumps stay excluded (they do not ship in the package).

Trade-off (accepted): because versions are centrally managed, a test/codegen dependency bump (e.g. xunit.v3) also republishes even though it does not ship - cheap version churn in exchange for never shipping a stale dependency. (The shipped library has effectively one runtime dependency, Microsoft.Extensions.Logging.Abstractions.)

WORKFLOW.md (glossary, D4.1, D8.2, 5A audit, S11) and AGENTS.md updated to match.

repo-config hardening

configure.shruleset_id distinguishes an absent ruleset from a real API error (lets gh surface its stderr; returns non-zero instead of a silent set -e abort), uses jq --arg, selects the first match inside jq (pipefail-safe), and pages the lookup (per_page=100). The repo-config README states the actual branch cleanup (auto-delete off so a develop -> main promotion does not delete develop; merged bot/feature branches cleaned up manually). Task comments aligned to the terse canonical form.

Verification

actionlint, markdownlint, shellcheck, bash -n clean; EOL preserved.

ptr727and others added 2 commits June 28, 2026 17:43
Bring repo-config in line with the hardened canonical: ruleset_id distinguishes an absent
ruleset from a real API error (lets gh surface its own stderr, returns non-zero instead of
a silent set -e abort), uses jq --arg, selects the first match inside jq (pipefail-safe),
and pages the lookup (per_page=100). The repo-config README states the actual branch
cleanup (auto-delete off so a develop -> main promotion does not delete develop; merged
bot/feature branches are cleaned up manually). Also aligns the validate/test-pr task
comments to the terse canonical form.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Add Directory.Packages.props to the publisher's shipped-input paths. A NuGet version
cannot be re-pushed, so (unlike a Docker image with a weekly base refresh) the only way the
published package's declared dependencies get a security/patch update is to republish when
a dependency bumps. GitHub-Actions bumps stay excluded - they do not ship in the package.
Update WORKFLOW.md (glossary, D4.1, D8.2, 5A audit, S11) and AGENTS.md to match.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 29, 2026 00:44

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the repo’s CI/publish contract so dependency bumps trigger a republish (to keep NuGet dependency constraints current), and hardens the repo-config configuration script for more reliable auditing/apply behavior.

Changes:

  • Treat Directory.Packages.props as a shipped input so merges that bump dependencies auto-publish on main/develop.
  • Harden repo-config/configure.sh (ruleset lookup paging/error behavior, jq safety, explicit “no linear history” assertion for main, improved secrets audit behavior).
  • Adjust CI workflows: skip jobs on branch-deletion push events; simplify workflow lint step configuration.

Reviewed changes

Copilot reviewed 7 out of 7 changed files in this pull request and generated 3 comments.

Show a summary per file
FileDescription
WORKFLOW.mdDocuments dependency-bump republish behavior and updates the shipped-input inclusion list.
AGENTS.mdUpdates the “merging releases” guidance to include dependency bumps as shipped inputs.
.github/workflows/publish-release.ymlAdds Directory.Packages.props to the publish on.push.paths inclusion list.
.github/workflows/test-pull-request.ymlSkips CI jobs on branch-deletion push events to avoid all-zero SHA failures.
.github/workflows/validate-task.ymlSimplifies the actionlint step configuration.
repo-config/configure.shHardens repo configuration auditing/apply logic and adds jq_lacks.
repo-config/README.mdClarifies branch auto-delete behavior and cleanup expectations.

Comment threadrepo-config/configure.sh Outdated
Comment threadrepo-config/configure.sh Outdated
Comment threadrepo-config/configure.sh Outdated
jq_lacks now propagates a real jq error (exit >1) instead of treating it as "lacks", so a
malformed filter/input fails the assert loudly rather than passing. check_secrets stops
suppressing gh's stderr (so the API/auth failure cause is visible, like ruleset_id) and its
comment matches the actual fail-fast behavior.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comment threadrepo-config/README.md Outdated
This repo's merge-bot merges with `gh pr merge --delete-branch`, so merged bot branches ARE
deleted (verified: no leftover dependabot/* branches). Distinguish the repo-wide auto-delete
setting (off, so a develop -> main promotion does not delete develop) from the explicit
per-merge deletion the merge-bot/maintainer performs.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated no new comments.

@ptr727
ptr727 merged commit 8b3a0cf into developJun 29, 2026
11 checks passed
@ptr727
ptr727 deleted the feature/publish-dep-currency branch June 29, 2026 00:57
ptr727 added a commit that referenced this pull request Jun 29, 2026
Capture jq's exit code with `|| rc=$?` (a list is exempt from errexit)
so an exit-1 no-match returns 'lacks' rather than risking a `set -e`
abort outside a conditional, while still propagating a real jq error
(>1). Verified under `set -euo pipefail` for match / no-match /
jq-error. Follow-up to PR #211.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
ptr727 added a commit that referenced this pull request Jun 29, 2026
Narrow the publish-release header comment - a package-version
(Directory.Packages.props) bump republishes; only a GitHub-Actions
Dependabot bump does not. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
ptr727 added a commit that referenced this pull request Jun 29, 2026
WORKFLOW.md said validate/smoke-build run unconditionally, but they
carry a `!github.event.deleted` guard. Note the branch-deletion
exception in the architecture section, D1.1, and the 5A audit, and add
scenario S16. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
ptr727 added a commit that referenced this pull request Jun 29, 2026
checkout/build fail -> fails. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
ptr727 added a commit that referenced this pull request Jun 29, 2026
Section 0's model-at-a-glance omitted package versions from the
shipped-input list (the glossary/D4.1 include them). Add it. Follow-up
to #211/#212.
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
ptr727 added a commit that referenced this pull request Jun 29, 2026
The on.push.paths inclusion list is below the header comment; change
'add a path above' to 'add a path to that list'. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Republish on dependency bumps; harden configure.sh by ptr727 · Pull Request #211 · ptr727/LanguageTags · GitHub
Skip to content

Republish on dependency bumps; harden configure.sh - #211

Merged
ptr727 merged 4 commits into
developfrom
feature/publish-dep-currency
Jun 29, 2026
Merged

Republish on dependency bumps; harden configure.sh#211
ptr727 merged 4 commits into
developfrom
feature/publish-dep-currency

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Keeps the push-self-publish model (correct for NuGet - there is no Docker-style refresh, and a NuGet version can't be re-pushed) and closes the stale-dependency window, plus brings repo-config in line with the hardened canonical.

Dependency currency

A NuGet package's declared dependencies only update when a new version is published. With no scheduled rebuild possible, a merged dependency bump must republish or the package keeps shipping old/vulnerable dependency constraints. So Directory.Packages.props is now a shipped input: a dependency bump on main/develop auto-publishes that branch, keeping the package current. GitHub-Actions bumps stay excluded (they do not ship in the package).

Trade-off (accepted): because versions are centrally managed, a test/codegen dependency bump (e.g. xunit.v3) also republishes even though it does not ship - cheap version churn in exchange for never shipping a stale dependency. (The shipped library has effectively one runtime dependency, Microsoft.Extensions.Logging.Abstractions.)

WORKFLOW.md (glossary, D4.1, D8.2, 5A audit, S11) and AGENTS.md updated to match.

repo-config hardening

configure.shruleset_id distinguishes an absent ruleset from a real API error (lets gh surface its stderr; returns non-zero instead of a silent set -e abort), uses jq --arg, selects the first match inside jq (pipefail-safe), and pages the lookup (per_page=100). The repo-config README states the actual branch cleanup (auto-delete off so a develop -> main promotion does not delete develop; merged bot/feature branches cleaned up manually). Task comments aligned to the terse canonical form.

Verification

actionlint, markdownlint, shellcheck, bash -n clean; EOL preserved.

ptr727and others added 2 commits June 28, 2026 17:43
Bring repo-config in line with the hardened canonical: ruleset_id distinguishes an absent
ruleset from a real API error (lets gh surface its own stderr, returns non-zero instead of
a silent set -e abort), uses jq --arg, selects the first match inside jq (pipefail-safe),
and pages the lookup (per_page=100). The repo-config README states the actual branch
cleanup (auto-delete off so a develop -> main promotion does not delete develop; merged
bot/feature branches are cleaned up manually). Also aligns the validate/test-pr task
comments to the terse canonical form.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Add Directory.Packages.props to the publisher's shipped-input paths. A NuGet version
cannot be re-pushed, so (unlike a Docker image with a weekly base refresh) the only way the
published package's declared dependencies get a security/patch update is to republish when
a dependency bumps. GitHub-Actions bumps stay excluded - they do not ship in the package.
Update WORKFLOW.md (glossary, D4.1, D8.2, 5A audit, S11) and AGENTS.md to match.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 29, 2026 00:44

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the repo’s CI/publish contract so dependency bumps trigger a republish (to keep NuGet dependency constraints current), and hardens the repo-config configuration script for more reliable auditing/apply behavior.

Changes:

  • Treat Directory.Packages.props as a shipped input so merges that bump dependencies auto-publish on main/develop.
  • Harden repo-config/configure.sh (ruleset lookup paging/error behavior, jq safety, explicit “no linear history” assertion for main, improved secrets audit behavior).
  • Adjust CI workflows: skip jobs on branch-deletion push events; simplify workflow lint step configuration.

Reviewed changes

Copilot reviewed 7 out of 7 changed files in this pull request and generated 3 comments.

Show a summary per file
FileDescription
WORKFLOW.mdDocuments dependency-bump republish behavior and updates the shipped-input inclusion list.
AGENTS.mdUpdates the “merging releases” guidance to include dependency bumps as shipped inputs.
.github/workflows/publish-release.ymlAdds Directory.Packages.props to the publish on.push.paths inclusion list.
.github/workflows/test-pull-request.ymlSkips CI jobs on branch-deletion push events to avoid all-zero SHA failures.
.github/workflows/validate-task.ymlSimplifies the actionlint step configuration.
repo-config/configure.shHardens repo configuration auditing/apply logic and adds jq_lacks.
repo-config/README.mdClarifies branch auto-delete behavior and cleanup expectations.

Comment threadrepo-config/configure.sh Outdated
Comment threadrepo-config/configure.sh Outdated
Comment threadrepo-config/configure.sh Outdated
jq_lacks now propagates a real jq error (exit >1) instead of treating it as "lacks", so a
malformed filter/input fails the assert loudly rather than passing. check_secrets stops
suppressing gh's stderr (so the API/auth failure cause is visible, like ruleset_id) and its
comment matches the actual fail-fast behavior.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comment threadrepo-config/README.md Outdated
This repo's merge-bot merges with `gh pr merge --delete-branch`, so merged bot branches ARE
deleted (verified: no leftover dependabot/* branches). Distinguish the repo-wide auto-delete
setting (off, so a develop -> main promotion does not delete develop) from the explicit
per-merge deletion the merge-bot/maintainer performs.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated no new comments.

@ptr727
ptr727 merged commit 8b3a0cf into developJun 29, 2026
11 checks passed
@ptr727
ptr727 deleted the feature/publish-dep-currency branch June 29, 2026 00:57
ptr727 added a commit that referenced this pull request Jun 29, 2026
Capture jq's exit code with `|| rc=$?` (a list is exempt from errexit)
so an exit-1 no-match returns 'lacks' rather than risking a `set -e`
abort outside a conditional, while still propagating a real jq error
(>1). Verified under `set -euo pipefail` for match / no-match /
jq-error. Follow-up to PR #211.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
ptr727 added a commit that referenced this pull request Jun 29, 2026
Narrow the publish-release header comment - a package-version
(Directory.Packages.props) bump republishes; only a GitHub-Actions
Dependabot bump does not. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
ptr727 added a commit that referenced this pull request Jun 29, 2026
WORKFLOW.md said validate/smoke-build run unconditionally, but they
carry a `!github.event.deleted` guard. Note the branch-deletion
exception in the architecture section, D1.1, and the 5A audit, and add
scenario S16. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
ptr727 added a commit that referenced this pull request Jun 29, 2026
checkout/build fail -> fails. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
ptr727 added a commit that referenced this pull request Jun 29, 2026
Section 0's model-at-a-glance omitted package versions from the
shipped-input list (the glossary/D4.1 include them). Add it. Follow-up
to #211/#212.
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
ptr727 added a commit that referenced this pull request Jun 29, 2026
The on.push.paths inclusion list is below the header comment; change
'add a path above' to 'add a path to that list'. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); Republish on dependency bumps; harden configure.sh by ptr727 · Pull Request #211 · ptr727/LanguageTags · GitHub
Skip to content

Republish on dependency bumps; harden configure.sh - #211

Merged
ptr727 merged 4 commits into
developfrom
feature/publish-dep-currency
Jun 29, 2026
Merged

Republish on dependency bumps; harden configure.sh#211
ptr727 merged 4 commits into
developfrom
feature/publish-dep-currency

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Keeps the push-self-publish model (correct for NuGet - there is no Docker-style refresh, and a NuGet version can't be re-pushed) and closes the stale-dependency window, plus brings repo-config in line with the hardened canonical.

Dependency currency

A NuGet package's declared dependencies only update when a new version is published. With no scheduled rebuild possible, a merged dependency bump must republish or the package keeps shipping old/vulnerable dependency constraints. So Directory.Packages.props is now a shipped input: a dependency bump on main/develop auto-publishes that branch, keeping the package current. GitHub-Actions bumps stay excluded (they do not ship in the package).

Trade-off (accepted): because versions are centrally managed, a test/codegen dependency bump (e.g. xunit.v3) also republishes even though it does not ship - cheap version churn in exchange for never shipping a stale dependency. (The shipped library has effectively one runtime dependency, Microsoft.Extensions.Logging.Abstractions.)

WORKFLOW.md (glossary, D4.1, D8.2, 5A audit, S11) and AGENTS.md updated to match.

repo-config hardening

configure.shruleset_id distinguishes an absent ruleset from a real API error (lets gh surface its stderr; returns non-zero instead of a silent set -e abort), uses jq --arg, selects the first match inside jq (pipefail-safe), and pages the lookup (per_page=100). The repo-config README states the actual branch cleanup (auto-delete off so a develop -> main promotion does not delete develop; merged bot/feature branches cleaned up manually). Task comments aligned to the terse canonical form.

Verification

actionlint, markdownlint, shellcheck, bash -n clean; EOL preserved.

ptr727and others added 2 commits June 28, 2026 17:43
Bring repo-config in line with the hardened canonical: ruleset_id distinguishes an absent
ruleset from a real API error (lets gh surface its own stderr, returns non-zero instead of
a silent set -e abort), uses jq --arg, selects the first match inside jq (pipefail-safe),
and pages the lookup (per_page=100). The repo-config README states the actual branch
cleanup (auto-delete off so a develop -> main promotion does not delete develop; merged
bot/feature branches are cleaned up manually). Also aligns the validate/test-pr task
comments to the terse canonical form.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Add Directory.Packages.props to the publisher's shipped-input paths. A NuGet version
cannot be re-pushed, so (unlike a Docker image with a weekly base refresh) the only way the
published package's declared dependencies get a security/patch update is to republish when
a dependency bumps. GitHub-Actions bumps stay excluded - they do not ship in the package.
Update WORKFLOW.md (glossary, D4.1, D8.2, 5A audit, S11) and AGENTS.md to match.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 29, 2026 00:44

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the repo’s CI/publish contract so dependency bumps trigger a republish (to keep NuGet dependency constraints current), and hardens the repo-config configuration script for more reliable auditing/apply behavior.

Changes:

  • Treat Directory.Packages.props as a shipped input so merges that bump dependencies auto-publish on main/develop.
  • Harden repo-config/configure.sh (ruleset lookup paging/error behavior, jq safety, explicit “no linear history” assertion for main, improved secrets audit behavior).
  • Adjust CI workflows: skip jobs on branch-deletion push events; simplify workflow lint step configuration.

Reviewed changes

Copilot reviewed 7 out of 7 changed files in this pull request and generated 3 comments.

Show a summary per file
FileDescription
WORKFLOW.mdDocuments dependency-bump republish behavior and updates the shipped-input inclusion list.
AGENTS.mdUpdates the “merging releases” guidance to include dependency bumps as shipped inputs.
.github/workflows/publish-release.ymlAdds Directory.Packages.props to the publish on.push.paths inclusion list.
.github/workflows/test-pull-request.ymlSkips CI jobs on branch-deletion push events to avoid all-zero SHA failures.
.github/workflows/validate-task.ymlSimplifies the actionlint step configuration.
repo-config/configure.shHardens repo configuration auditing/apply logic and adds jq_lacks.
repo-config/README.mdClarifies branch auto-delete behavior and cleanup expectations.

Comment threadrepo-config/configure.sh Outdated
Comment threadrepo-config/configure.sh Outdated
Comment threadrepo-config/configure.sh Outdated
jq_lacks now propagates a real jq error (exit >1) instead of treating it as "lacks", so a
malformed filter/input fails the assert loudly rather than passing. check_secrets stops
suppressing gh's stderr (so the API/auth failure cause is visible, like ruleset_id) and its
comment matches the actual fail-fast behavior.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comment threadrepo-config/README.md Outdated
This repo's merge-bot merges with `gh pr merge --delete-branch`, so merged bot branches ARE
deleted (verified: no leftover dependabot/* branches). Distinguish the repo-wide auto-delete
setting (off, so a develop -> main promotion does not delete develop) from the explicit
per-merge deletion the merge-bot/maintainer performs.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated no new comments.

@ptr727
ptr727 merged commit 8b3a0cf into developJun 29, 2026
11 checks passed
@ptr727
ptr727 deleted the feature/publish-dep-currency branch June 29, 2026 00:57
ptr727 added a commit that referenced this pull request Jun 29, 2026
Capture jq's exit code with `|| rc=$?` (a list is exempt from errexit)
so an exit-1 no-match returns 'lacks' rather than risking a `set -e`
abort outside a conditional, while still propagating a real jq error
(>1). Verified under `set -euo pipefail` for match / no-match /
jq-error. Follow-up to PR #211.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
ptr727 added a commit that referenced this pull request Jun 29, 2026
Narrow the publish-release header comment - a package-version
(Directory.Packages.props) bump republishes; only a GitHub-Actions
Dependabot bump does not. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
ptr727 added a commit that referenced this pull request Jun 29, 2026
WORKFLOW.md said validate/smoke-build run unconditionally, but they
carry a `!github.event.deleted` guard. Note the branch-deletion
exception in the architecture section, D1.1, and the 5A audit, and add
scenario S16. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
ptr727 added a commit that referenced this pull request Jun 29, 2026
checkout/build fail -> fails. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
ptr727 added a commit that referenced this pull request Jun 29, 2026
Section 0's model-at-a-glance omitted package versions from the
shipped-input list (the glossary/D4.1 include them). Add it. Follow-up
to #211/#212.
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
ptr727 added a commit that referenced this pull request Jun 29, 2026
The on.push.paths inclusion list is below the header comment; change
'add a path above' to 'add a path to that list'. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727