Skip to content

Promote develop to main: dependency-currency publish + configure.sh hardening - #212

Merged
ptr727 merged 7 commits into
mainfrom
develop
Jun 29, 2026
Merged

Promote develop to main: dependency-currency publish + configure.sh hardening#212
ptr727 merged 7 commits into
mainfrom
develop

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Promotes PR #211 from develop to main.

What lands on main

  • Dependency currency:Directory.Packages.props is now a shipped input, so a merged dependency bump republishes and the published package's declared dependencies stay current (a NuGet version can't be re-pushed, so there's no Docker-style refresh). GitHub-Actions bumps stay excluded. WORKFLOW.md/AGENTS.md updated.
  • configure.sh hardening:ruleset_id (error-distinction, jq --arg, pipefail-safe, per_page=100), jq_lacks (propagates real jq errors), check_secrets (surfaces gh's stderr, accurate comment).
  • repo-config README states the actual branch cleanup (auto-delete setting off to protect develop; merge-bot deletes bot branches with --delete-branch).

Standard promotion PR with review (no admin bypass). No library code change.

Keeps the push-self-publish model (correct for NuGet - there is no
Docker-style refresh, and a NuGet version can't be re-pushed) and closes
the stale-dependency window, plus brings repo-config in line with the
hardened canonical.
## Dependency currency
A NuGet package's declared dependencies only update when a new version
is published. With no scheduled rebuild possible, a merged dependency
bump must republish or the package keeps shipping old/vulnerable
dependency constraints. So **`Directory.Packages.props` is now a shipped
input**: a dependency bump on main/develop auto-publishes that branch,
keeping the package current. GitHub-Actions bumps stay excluded (they do
not ship in the package).
Trade-off (accepted): because versions are centrally managed, a
test/codegen dependency bump (e.g. `xunit.v3`) also republishes even
though it does not ship - cheap version churn in exchange for never
shipping a stale dependency. (The shipped library has effectively one
runtime dependency, `Microsoft.Extensions.Logging.Abstractions`.)
WORKFLOW.md (glossary, D4.1, D8.2, 5A audit, S11) and AGENTS.md updated
to match.
## repo-config hardening
`configure.sh` `ruleset_id` distinguishes an absent ruleset from a real
API error (lets gh surface its stderr; returns non-zero instead of a
silent `set -e` abort), uses `jq --arg`, selects the first match inside
jq (pipefail-safe), and pages the lookup (`per_page=100`). The
repo-config README states the actual branch cleanup (auto-delete off so
a `develop -> main` promotion does not delete `develop`; merged
bot/feature branches cleaned up manually). Task comments aligned to the
terse canonical form.
## Verification
actionlint, markdownlint, shellcheck, `bash -n` clean; EOL preserved.
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 29, 2026 00:57

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Promotes develop to main while updating the release trigger definition so dependency version bumps republish the NuGet package, and hardens repo-config/configure.sh plus a few CI/documentation adjustments.

Changes:

  • Treat Directory.Packages.props as a shipped input (docs + publish workflow path filter) so dependency bumps republish and keep declared dependencies current.
  • Harden repo-config/configure.sh around ruleset lookup, jq error handling, and secrets listing behavior.
  • CI/docs tweaks: skip PR test workflow jobs on branch-deletion pushes; simplify actionlint step configuration and refresh related documentation text.

Reviewed changes

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Show a summary per file
FileDescription
WORKFLOW.mdUpdates shipped-input definition and operational guarantees to include Directory.Packages.props and explain the republish rationale.
repo-config/README.mdClarifies branch deletion behavior (repo setting off; explicit per-merge deletion instead).
repo-config/configure.shHardens ruleset lookup, adds jq_lacks, and improves secrets-check error reporting.
AGENTS.mdUpdates merge/release guidance to reflect dependency bumps now triggering publish.
.github/workflows/validate-task.ymlSimplifies workflow-lint step configuration for actionlint.
.github/workflows/test-pull-request.ymlSkips reusable-workflow jobs (and the status aggregator) on deleted-branch push events.
.github/workflows/publish-release.ymlAdds Directory.Packages.props to the shipped-input on.push.paths trigger and updates comments accordingly.

Comment threadrepo-config/configure.sh Outdated
Capture jq's exit code with `|| rc=$?` (a list is exempt from errexit)
so an exit-1 no-match returns 'lacks' rather than risking a `set -e`
abort outside a conditional, while still propagating a real jq error
(>1). Verified under `set -euo pipefail` for match / no-match /
jq-error. Follow-up to PR #211.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comment thread.github/workflows/publish-release.yml Outdated
Narrow the publish-release header comment - a package-version
(Directory.Packages.props) bump republishes; only a GitHub-Actions
Dependabot bump does not. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comment thread.github/workflows/test-pull-request.yml Outdated
WORKFLOW.md said validate/smoke-build run unconditionally, but they
carry a `!github.event.deleted` guard. Note the branch-deletion
exception in the architecture section, D1.1, and the 5A audit, and add
scenario S16. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comment thread.github/workflows/test-pull-request.yml Outdated
checkout/build fail -> fails. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comment threadWORKFLOW.md
Section 0's model-at-a-glance omitted package versions from the
shipped-input list (the glossary/D4.1 include them). Add it. Follow-up
to #211/#212.
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comments suppressed due to low confidence (1)

.github/workflows/validate-task.yml:73

  • The actionlint step no longer pins the underlying actionlint binary version (the version input was removed). Per raven-actions/actionlint docs, omitting version defaults to latest, which makes lint results non-reproducible and can cause CI to change behavior without a repo change. Pin version to a specific actionlint release and bump it intentionally alongside the action SHA.
 - name: Lint workflows step
uses: raven-actions/actionlint@3d39aea434753780c3b3d4a1a31c854b4dbf49d7 # v2.2.0

Comment thread.github/workflows/publish-release.yml Outdated
The on.push.paths inclusion list is below the header comment; change
'add a path above' to 'add a path to that list'. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated no new comments.

@ptr727
ptr727 merged commit db387ac into mainJun 29, 2026
11 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Promote develop to main: dependency-currency publish + configure.sh hardening by ptr727 · Pull Request #212 · ptr727/LanguageTags · GitHub
Skip to content

Promote develop to main: dependency-currency publish + configure.sh hardening - #212

Merged
ptr727 merged 7 commits into
mainfrom
develop
Jun 29, 2026
Merged

Promote develop to main: dependency-currency publish + configure.sh hardening#212
ptr727 merged 7 commits into
mainfrom
develop

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Promotes PR #211 from develop to main.

What lands on main

  • Dependency currency:Directory.Packages.props is now a shipped input, so a merged dependency bump republishes and the published package's declared dependencies stay current (a NuGet version can't be re-pushed, so there's no Docker-style refresh). GitHub-Actions bumps stay excluded. WORKFLOW.md/AGENTS.md updated.
  • configure.sh hardening:ruleset_id (error-distinction, jq --arg, pipefail-safe, per_page=100), jq_lacks (propagates real jq errors), check_secrets (surfaces gh's stderr, accurate comment).
  • repo-config README states the actual branch cleanup (auto-delete setting off to protect develop; merge-bot deletes bot branches with --delete-branch).

Standard promotion PR with review (no admin bypass). No library code change.

Keeps the push-self-publish model (correct for NuGet - there is no
Docker-style refresh, and a NuGet version can't be re-pushed) and closes
the stale-dependency window, plus brings repo-config in line with the
hardened canonical.
## Dependency currency
A NuGet package's declared dependencies only update when a new version
is published. With no scheduled rebuild possible, a merged dependency
bump must republish or the package keeps shipping old/vulnerable
dependency constraints. So **`Directory.Packages.props` is now a shipped
input**: a dependency bump on main/develop auto-publishes that branch,
keeping the package current. GitHub-Actions bumps stay excluded (they do
not ship in the package).
Trade-off (accepted): because versions are centrally managed, a
test/codegen dependency bump (e.g. `xunit.v3`) also republishes even
though it does not ship - cheap version churn in exchange for never
shipping a stale dependency. (The shipped library has effectively one
runtime dependency, `Microsoft.Extensions.Logging.Abstractions`.)
WORKFLOW.md (glossary, D4.1, D8.2, 5A audit, S11) and AGENTS.md updated
to match.
## repo-config hardening
`configure.sh` `ruleset_id` distinguishes an absent ruleset from a real
API error (lets gh surface its stderr; returns non-zero instead of a
silent `set -e` abort), uses `jq --arg`, selects the first match inside
jq (pipefail-safe), and pages the lookup (`per_page=100`). The
repo-config README states the actual branch cleanup (auto-delete off so
a `develop -> main` promotion does not delete `develop`; merged
bot/feature branches cleaned up manually). Task comments aligned to the
terse canonical form.
## Verification
actionlint, markdownlint, shellcheck, `bash -n` clean; EOL preserved.
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 29, 2026 00:57

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Promotes develop to main while updating the release trigger definition so dependency version bumps republish the NuGet package, and hardens repo-config/configure.sh plus a few CI/documentation adjustments.

Changes:

  • Treat Directory.Packages.props as a shipped input (docs + publish workflow path filter) so dependency bumps republish and keep declared dependencies current.
  • Harden repo-config/configure.sh around ruleset lookup, jq error handling, and secrets listing behavior.
  • CI/docs tweaks: skip PR test workflow jobs on branch-deletion pushes; simplify actionlint step configuration and refresh related documentation text.

Reviewed changes

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Show a summary per file
FileDescription
WORKFLOW.mdUpdates shipped-input definition and operational guarantees to include Directory.Packages.props and explain the republish rationale.
repo-config/README.mdClarifies branch deletion behavior (repo setting off; explicit per-merge deletion instead).
repo-config/configure.shHardens ruleset lookup, adds jq_lacks, and improves secrets-check error reporting.
AGENTS.mdUpdates merge/release guidance to reflect dependency bumps now triggering publish.
.github/workflows/validate-task.ymlSimplifies workflow-lint step configuration for actionlint.
.github/workflows/test-pull-request.ymlSkips reusable-workflow jobs (and the status aggregator) on deleted-branch push events.
.github/workflows/publish-release.ymlAdds Directory.Packages.props to the shipped-input on.push.paths trigger and updates comments accordingly.

Comment threadrepo-config/configure.sh Outdated
Capture jq's exit code with `|| rc=$?` (a list is exempt from errexit)
so an exit-1 no-match returns 'lacks' rather than risking a `set -e`
abort outside a conditional, while still propagating a real jq error
(>1). Verified under `set -euo pipefail` for match / no-match /
jq-error. Follow-up to PR #211.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comment thread.github/workflows/publish-release.yml Outdated
Narrow the publish-release header comment - a package-version
(Directory.Packages.props) bump republishes; only a GitHub-Actions
Dependabot bump does not. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comment thread.github/workflows/test-pull-request.yml Outdated
WORKFLOW.md said validate/smoke-build run unconditionally, but they
carry a `!github.event.deleted` guard. Note the branch-deletion
exception in the architecture section, D1.1, and the 5A audit, and add
scenario S16. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comment thread.github/workflows/test-pull-request.yml Outdated
checkout/build fail -> fails. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comment threadWORKFLOW.md
Section 0's model-at-a-glance omitted package versions from the
shipped-input list (the glossary/D4.1 include them). Add it. Follow-up
to #211/#212.
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comments suppressed due to low confidence (1)

.github/workflows/validate-task.yml:73

  • The actionlint step no longer pins the underlying actionlint binary version (the version input was removed). Per raven-actions/actionlint docs, omitting version defaults to latest, which makes lint results non-reproducible and can cause CI to change behavior without a repo change. Pin version to a specific actionlint release and bump it intentionally alongside the action SHA.
 - name: Lint workflows step
uses: raven-actions/actionlint@3d39aea434753780c3b3d4a1a31c854b4dbf49d7 # v2.2.0

Comment thread.github/workflows/publish-release.yml Outdated
The on.push.paths inclusion list is below the header comment; change
'add a path above' to 'add a path to that list'. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated no new comments.

@ptr727
ptr727 merged commit db387ac into mainJun 29, 2026
11 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Promote develop to main: dependency-currency publish + configure.sh hardening by ptr727 · Pull Request #212 · ptr727/LanguageTags · GitHub
Skip to content

Promote develop to main: dependency-currency publish + configure.sh hardening - #212

Merged
ptr727 merged 7 commits into
mainfrom
develop
Jun 29, 2026
Merged

Promote develop to main: dependency-currency publish + configure.sh hardening#212
ptr727 merged 7 commits into
mainfrom
develop

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Promotes PR #211 from develop to main.

What lands on main

  • Dependency currency:Directory.Packages.props is now a shipped input, so a merged dependency bump republishes and the published package's declared dependencies stay current (a NuGet version can't be re-pushed, so there's no Docker-style refresh). GitHub-Actions bumps stay excluded. WORKFLOW.md/AGENTS.md updated.
  • configure.sh hardening:ruleset_id (error-distinction, jq --arg, pipefail-safe, per_page=100), jq_lacks (propagates real jq errors), check_secrets (surfaces gh's stderr, accurate comment).
  • repo-config README states the actual branch cleanup (auto-delete setting off to protect develop; merge-bot deletes bot branches with --delete-branch).

Standard promotion PR with review (no admin bypass). No library code change.

Keeps the push-self-publish model (correct for NuGet - there is no
Docker-style refresh, and a NuGet version can't be re-pushed) and closes
the stale-dependency window, plus brings repo-config in line with the
hardened canonical.
## Dependency currency
A NuGet package's declared dependencies only update when a new version
is published. With no scheduled rebuild possible, a merged dependency
bump must republish or the package keeps shipping old/vulnerable
dependency constraints. So **`Directory.Packages.props` is now a shipped
input**: a dependency bump on main/develop auto-publishes that branch,
keeping the package current. GitHub-Actions bumps stay excluded (they do
not ship in the package).
Trade-off (accepted): because versions are centrally managed, a
test/codegen dependency bump (e.g. `xunit.v3`) also republishes even
though it does not ship - cheap version churn in exchange for never
shipping a stale dependency. (The shipped library has effectively one
runtime dependency, `Microsoft.Extensions.Logging.Abstractions`.)
WORKFLOW.md (glossary, D4.1, D8.2, 5A audit, S11) and AGENTS.md updated
to match.
## repo-config hardening
`configure.sh` `ruleset_id` distinguishes an absent ruleset from a real
API error (lets gh surface its stderr; returns non-zero instead of a
silent `set -e` abort), uses `jq --arg`, selects the first match inside
jq (pipefail-safe), and pages the lookup (`per_page=100`). The
repo-config README states the actual branch cleanup (auto-delete off so
a `develop -> main` promotion does not delete `develop`; merged
bot/feature branches cleaned up manually). Task comments aligned to the
terse canonical form.
## Verification
actionlint, markdownlint, shellcheck, `bash -n` clean; EOL preserved.
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 29, 2026 00:57

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Promotes develop to main while updating the release trigger definition so dependency version bumps republish the NuGet package, and hardens repo-config/configure.sh plus a few CI/documentation adjustments.

Changes:

  • Treat Directory.Packages.props as a shipped input (docs + publish workflow path filter) so dependency bumps republish and keep declared dependencies current.
  • Harden repo-config/configure.sh around ruleset lookup, jq error handling, and secrets listing behavior.
  • CI/docs tweaks: skip PR test workflow jobs on branch-deletion pushes; simplify actionlint step configuration and refresh related documentation text.

Reviewed changes

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Show a summary per file
FileDescription
WORKFLOW.mdUpdates shipped-input definition and operational guarantees to include Directory.Packages.props and explain the republish rationale.
repo-config/README.mdClarifies branch deletion behavior (repo setting off; explicit per-merge deletion instead).
repo-config/configure.shHardens ruleset lookup, adds jq_lacks, and improves secrets-check error reporting.
AGENTS.mdUpdates merge/release guidance to reflect dependency bumps now triggering publish.
.github/workflows/validate-task.ymlSimplifies workflow-lint step configuration for actionlint.
.github/workflows/test-pull-request.ymlSkips reusable-workflow jobs (and the status aggregator) on deleted-branch push events.
.github/workflows/publish-release.ymlAdds Directory.Packages.props to the shipped-input on.push.paths trigger and updates comments accordingly.

Comment threadrepo-config/configure.sh Outdated
Capture jq's exit code with `|| rc=$?` (a list is exempt from errexit)
so an exit-1 no-match returns 'lacks' rather than risking a `set -e`
abort outside a conditional, while still propagating a real jq error
(>1). Verified under `set -euo pipefail` for match / no-match /
jq-error. Follow-up to PR #211.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comment thread.github/workflows/publish-release.yml Outdated
Narrow the publish-release header comment - a package-version
(Directory.Packages.props) bump republishes; only a GitHub-Actions
Dependabot bump does not. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comment thread.github/workflows/test-pull-request.yml Outdated
WORKFLOW.md said validate/smoke-build run unconditionally, but they
carry a `!github.event.deleted` guard. Note the branch-deletion
exception in the architecture section, D1.1, and the 5A audit, and add
scenario S16. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comment thread.github/workflows/test-pull-request.yml Outdated
checkout/build fail -> fails. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comment threadWORKFLOW.md
Section 0's model-at-a-glance omitted package versions from the
shipped-input list (the glossary/D4.1 include them). Add it. Follow-up
to #211/#212.
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comments suppressed due to low confidence (1)

.github/workflows/validate-task.yml:73

  • The actionlint step no longer pins the underlying actionlint binary version (the version input was removed). Per raven-actions/actionlint docs, omitting version defaults to latest, which makes lint results non-reproducible and can cause CI to change behavior without a repo change. Pin version to a specific actionlint release and bump it intentionally alongside the action SHA.
 - name: Lint workflows step
uses: raven-actions/actionlint@3d39aea434753780c3b3d4a1a31c854b4dbf49d7 # v2.2.0

Comment thread.github/workflows/publish-release.yml Outdated
The on.push.paths inclusion list is below the header comment; change
'add a path above' to 'add a path to that list'. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated no new comments.

@ptr727
ptr727 merged commit db387ac into mainJun 29, 2026
11 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Promote develop to main: dependency-currency publish + configure.sh hardening by ptr727 · Pull Request #212 · ptr727/LanguageTags · GitHub
Skip to content

Promote develop to main: dependency-currency publish + configure.sh hardening - #212

Merged
ptr727 merged 7 commits into
mainfrom
develop
Jun 29, 2026
Merged

Promote develop to main: dependency-currency publish + configure.sh hardening#212
ptr727 merged 7 commits into
mainfrom
develop

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Promotes PR #211 from develop to main.

What lands on main

  • Dependency currency:Directory.Packages.props is now a shipped input, so a merged dependency bump republishes and the published package's declared dependencies stay current (a NuGet version can't be re-pushed, so there's no Docker-style refresh). GitHub-Actions bumps stay excluded. WORKFLOW.md/AGENTS.md updated.
  • configure.sh hardening:ruleset_id (error-distinction, jq --arg, pipefail-safe, per_page=100), jq_lacks (propagates real jq errors), check_secrets (surfaces gh's stderr, accurate comment).
  • repo-config README states the actual branch cleanup (auto-delete setting off to protect develop; merge-bot deletes bot branches with --delete-branch).

Standard promotion PR with review (no admin bypass). No library code change.

Keeps the push-self-publish model (correct for NuGet - there is no
Docker-style refresh, and a NuGet version can't be re-pushed) and closes
the stale-dependency window, plus brings repo-config in line with the
hardened canonical.
## Dependency currency
A NuGet package's declared dependencies only update when a new version
is published. With no scheduled rebuild possible, a merged dependency
bump must republish or the package keeps shipping old/vulnerable
dependency constraints. So **`Directory.Packages.props` is now a shipped
input**: a dependency bump on main/develop auto-publishes that branch,
keeping the package current. GitHub-Actions bumps stay excluded (they do
not ship in the package).
Trade-off (accepted): because versions are centrally managed, a
test/codegen dependency bump (e.g. `xunit.v3`) also republishes even
though it does not ship - cheap version churn in exchange for never
shipping a stale dependency. (The shipped library has effectively one
runtime dependency, `Microsoft.Extensions.Logging.Abstractions`.)
WORKFLOW.md (glossary, D4.1, D8.2, 5A audit, S11) and AGENTS.md updated
to match.
## repo-config hardening
`configure.sh` `ruleset_id` distinguishes an absent ruleset from a real
API error (lets gh surface its stderr; returns non-zero instead of a
silent `set -e` abort), uses `jq --arg`, selects the first match inside
jq (pipefail-safe), and pages the lookup (`per_page=100`). The
repo-config README states the actual branch cleanup (auto-delete off so
a `develop -> main` promotion does not delete `develop`; merged
bot/feature branches cleaned up manually). Task comments aligned to the
terse canonical form.
## Verification
actionlint, markdownlint, shellcheck, `bash -n` clean; EOL preserved.
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 29, 2026 00:57

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Promotes develop to main while updating the release trigger definition so dependency version bumps republish the NuGet package, and hardens repo-config/configure.sh plus a few CI/documentation adjustments.

Changes:

  • Treat Directory.Packages.props as a shipped input (docs + publish workflow path filter) so dependency bumps republish and keep declared dependencies current.
  • Harden repo-config/configure.sh around ruleset lookup, jq error handling, and secrets listing behavior.
  • CI/docs tweaks: skip PR test workflow jobs on branch-deletion pushes; simplify actionlint step configuration and refresh related documentation text.

Reviewed changes

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Show a summary per file
FileDescription
WORKFLOW.mdUpdates shipped-input definition and operational guarantees to include Directory.Packages.props and explain the republish rationale.
repo-config/README.mdClarifies branch deletion behavior (repo setting off; explicit per-merge deletion instead).
repo-config/configure.shHardens ruleset lookup, adds jq_lacks, and improves secrets-check error reporting.
AGENTS.mdUpdates merge/release guidance to reflect dependency bumps now triggering publish.
.github/workflows/validate-task.ymlSimplifies workflow-lint step configuration for actionlint.
.github/workflows/test-pull-request.ymlSkips reusable-workflow jobs (and the status aggregator) on deleted-branch push events.
.github/workflows/publish-release.ymlAdds Directory.Packages.props to the shipped-input on.push.paths trigger and updates comments accordingly.

Comment threadrepo-config/configure.sh Outdated
Capture jq's exit code with `|| rc=$?` (a list is exempt from errexit)
so an exit-1 no-match returns 'lacks' rather than risking a `set -e`
abort outside a conditional, while still propagating a real jq error
(>1). Verified under `set -euo pipefail` for match / no-match /
jq-error. Follow-up to PR #211.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comment thread.github/workflows/publish-release.yml Outdated
Narrow the publish-release header comment - a package-version
(Directory.Packages.props) bump republishes; only a GitHub-Actions
Dependabot bump does not. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comment thread.github/workflows/test-pull-request.yml Outdated
WORKFLOW.md said validate/smoke-build run unconditionally, but they
carry a `!github.event.deleted` guard. Note the branch-deletion
exception in the architecture section, D1.1, and the 5A audit, and add
scenario S16. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comment thread.github/workflows/test-pull-request.yml Outdated
checkout/build fail -> fails. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comment threadWORKFLOW.md
Section 0's model-at-a-glance omitted package versions from the
shipped-input list (the glossary/D4.1 include them). Add it. Follow-up
to #211/#212.
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comments suppressed due to low confidence (1)

.github/workflows/validate-task.yml:73

  • The actionlint step no longer pins the underlying actionlint binary version (the version input was removed). Per raven-actions/actionlint docs, omitting version defaults to latest, which makes lint results non-reproducible and can cause CI to change behavior without a repo change. Pin version to a specific actionlint release and bump it intentionally alongside the action SHA.
 - name: Lint workflows step
uses: raven-actions/actionlint@3d39aea434753780c3b3d4a1a31c854b4dbf49d7 # v2.2.0

Comment thread.github/workflows/publish-release.yml Outdated
The on.push.paths inclusion list is below the header comment; change
'add a path above' to 'add a path to that list'. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated no new comments.

@ptr727
ptr727 merged commit db387ac into mainJun 29, 2026
11 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' Promote develop to main: dependency-currency publish + configure.sh hardening by ptr727 · Pull Request #212 · ptr727/LanguageTags · GitHub
Skip to content

Promote develop to main: dependency-currency publish + configure.sh hardening - #212

Merged
ptr727 merged 7 commits into
mainfrom
develop
Jun 29, 2026
Merged

Promote develop to main: dependency-currency publish + configure.sh hardening#212
ptr727 merged 7 commits into
mainfrom
develop

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Promotes PR #211 from develop to main.

What lands on main

  • Dependency currency:Directory.Packages.props is now a shipped input, so a merged dependency bump republishes and the published package's declared dependencies stay current (a NuGet version can't be re-pushed, so there's no Docker-style refresh). GitHub-Actions bumps stay excluded. WORKFLOW.md/AGENTS.md updated.
  • configure.sh hardening:ruleset_id (error-distinction, jq --arg, pipefail-safe, per_page=100), jq_lacks (propagates real jq errors), check_secrets (surfaces gh's stderr, accurate comment).
  • repo-config README states the actual branch cleanup (auto-delete setting off to protect develop; merge-bot deletes bot branches with --delete-branch).

Standard promotion PR with review (no admin bypass). No library code change.

Keeps the push-self-publish model (correct for NuGet - there is no
Docker-style refresh, and a NuGet version can't be re-pushed) and closes
the stale-dependency window, plus brings repo-config in line with the
hardened canonical.
## Dependency currency
A NuGet package's declared dependencies only update when a new version
is published. With no scheduled rebuild possible, a merged dependency
bump must republish or the package keeps shipping old/vulnerable
dependency constraints. So **`Directory.Packages.props` is now a shipped
input**: a dependency bump on main/develop auto-publishes that branch,
keeping the package current. GitHub-Actions bumps stay excluded (they do
not ship in the package).
Trade-off (accepted): because versions are centrally managed, a
test/codegen dependency bump (e.g. `xunit.v3`) also republishes even
though it does not ship - cheap version churn in exchange for never
shipping a stale dependency. (The shipped library has effectively one
runtime dependency, `Microsoft.Extensions.Logging.Abstractions`.)
WORKFLOW.md (glossary, D4.1, D8.2, 5A audit, S11) and AGENTS.md updated
to match.
## repo-config hardening
`configure.sh` `ruleset_id` distinguishes an absent ruleset from a real
API error (lets gh surface its stderr; returns non-zero instead of a
silent `set -e` abort), uses `jq --arg`, selects the first match inside
jq (pipefail-safe), and pages the lookup (`per_page=100`). The
repo-config README states the actual branch cleanup (auto-delete off so
a `develop -> main` promotion does not delete `develop`; merged
bot/feature branches cleaned up manually). Task comments aligned to the
terse canonical form.
## Verification
actionlint, markdownlint, shellcheck, `bash -n` clean; EOL preserved.
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 29, 2026 00:57

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Promotes develop to main while updating the release trigger definition so dependency version bumps republish the NuGet package, and hardens repo-config/configure.sh plus a few CI/documentation adjustments.

Changes:

  • Treat Directory.Packages.props as a shipped input (docs + publish workflow path filter) so dependency bumps republish and keep declared dependencies current.
  • Harden repo-config/configure.sh around ruleset lookup, jq error handling, and secrets listing behavior.
  • CI/docs tweaks: skip PR test workflow jobs on branch-deletion pushes; simplify actionlint step configuration and refresh related documentation text.

Reviewed changes

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Show a summary per file
FileDescription
WORKFLOW.mdUpdates shipped-input definition and operational guarantees to include Directory.Packages.props and explain the republish rationale.
repo-config/README.mdClarifies branch deletion behavior (repo setting off; explicit per-merge deletion instead).
repo-config/configure.shHardens ruleset lookup, adds jq_lacks, and improves secrets-check error reporting.
AGENTS.mdUpdates merge/release guidance to reflect dependency bumps now triggering publish.
.github/workflows/validate-task.ymlSimplifies workflow-lint step configuration for actionlint.
.github/workflows/test-pull-request.ymlSkips reusable-workflow jobs (and the status aggregator) on deleted-branch push events.
.github/workflows/publish-release.ymlAdds Directory.Packages.props to the shipped-input on.push.paths trigger and updates comments accordingly.

Comment threadrepo-config/configure.sh Outdated
Capture jq's exit code with `|| rc=$?` (a list is exempt from errexit)
so an exit-1 no-match returns 'lacks' rather than risking a `set -e`
abort outside a conditional, while still propagating a real jq error
(>1). Verified under `set -euo pipefail` for match / no-match /
jq-error. Follow-up to PR #211.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comment thread.github/workflows/publish-release.yml Outdated
Narrow the publish-release header comment - a package-version
(Directory.Packages.props) bump republishes; only a GitHub-Actions
Dependabot bump does not. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comment thread.github/workflows/test-pull-request.yml Outdated
WORKFLOW.md said validate/smoke-build run unconditionally, but they
carry a `!github.event.deleted` guard. Note the branch-deletion
exception in the architecture section, D1.1, and the 5A audit, and add
scenario S16. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comment thread.github/workflows/test-pull-request.yml Outdated
checkout/build fail -> fails. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comment threadWORKFLOW.md
Section 0's model-at-a-glance omitted package versions from the
shipped-input list (the glossary/D4.1 include them). Add it. Follow-up
to #211/#212.
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comments suppressed due to low confidence (1)

.github/workflows/validate-task.yml:73

  • The actionlint step no longer pins the underlying actionlint binary version (the version input was removed). Per raven-actions/actionlint docs, omitting version defaults to latest, which makes lint results non-reproducible and can cause CI to change behavior without a repo change. Pin version to a specific actionlint release and bump it intentionally alongside the action SHA.
 - name: Lint workflows step
uses: raven-actions/actionlint@3d39aea434753780c3b3d4a1a31c854b4dbf49d7 # v2.2.0

Comment thread.github/workflows/publish-release.yml Outdated
The on.push.paths inclusion list is below the header comment; change
'add a path above' to 'add a path to that list'. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated no new comments.

@ptr727
ptr727 merged commit db387ac into mainJun 29, 2026
11 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Promote develop to main: dependency-currency publish + configure.sh hardening by ptr727 · Pull Request #212 · ptr727/LanguageTags · GitHub
Skip to content

Promote develop to main: dependency-currency publish + configure.sh hardening - #212

Merged
ptr727 merged 7 commits into
mainfrom
develop
Jun 29, 2026
Merged

Promote develop to main: dependency-currency publish + configure.sh hardening#212
ptr727 merged 7 commits into
mainfrom
develop

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Promotes PR #211 from develop to main.

What lands on main

  • Dependency currency:Directory.Packages.props is now a shipped input, so a merged dependency bump republishes and the published package's declared dependencies stay current (a NuGet version can't be re-pushed, so there's no Docker-style refresh). GitHub-Actions bumps stay excluded. WORKFLOW.md/AGENTS.md updated.
  • configure.sh hardening:ruleset_id (error-distinction, jq --arg, pipefail-safe, per_page=100), jq_lacks (propagates real jq errors), check_secrets (surfaces gh's stderr, accurate comment).
  • repo-config README states the actual branch cleanup (auto-delete setting off to protect develop; merge-bot deletes bot branches with --delete-branch).

Standard promotion PR with review (no admin bypass). No library code change.

Keeps the push-self-publish model (correct for NuGet - there is no
Docker-style refresh, and a NuGet version can't be re-pushed) and closes
the stale-dependency window, plus brings repo-config in line with the
hardened canonical.
## Dependency currency
A NuGet package's declared dependencies only update when a new version
is published. With no scheduled rebuild possible, a merged dependency
bump must republish or the package keeps shipping old/vulnerable
dependency constraints. So **`Directory.Packages.props` is now a shipped
input**: a dependency bump on main/develop auto-publishes that branch,
keeping the package current. GitHub-Actions bumps stay excluded (they do
not ship in the package).
Trade-off (accepted): because versions are centrally managed, a
test/codegen dependency bump (e.g. `xunit.v3`) also republishes even
though it does not ship - cheap version churn in exchange for never
shipping a stale dependency. (The shipped library has effectively one
runtime dependency, `Microsoft.Extensions.Logging.Abstractions`.)
WORKFLOW.md (glossary, D4.1, D8.2, 5A audit, S11) and AGENTS.md updated
to match.
## repo-config hardening
`configure.sh` `ruleset_id` distinguishes an absent ruleset from a real
API error (lets gh surface its stderr; returns non-zero instead of a
silent `set -e` abort), uses `jq --arg`, selects the first match inside
jq (pipefail-safe), and pages the lookup (`per_page=100`). The
repo-config README states the actual branch cleanup (auto-delete off so
a `develop -> main` promotion does not delete `develop`; merged
bot/feature branches cleaned up manually). Task comments aligned to the
terse canonical form.
## Verification
actionlint, markdownlint, shellcheck, `bash -n` clean; EOL preserved.
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 29, 2026 00:57

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Promotes develop to main while updating the release trigger definition so dependency version bumps republish the NuGet package, and hardens repo-config/configure.sh plus a few CI/documentation adjustments.

Changes:

  • Treat Directory.Packages.props as a shipped input (docs + publish workflow path filter) so dependency bumps republish and keep declared dependencies current.
  • Harden repo-config/configure.sh around ruleset lookup, jq error handling, and secrets listing behavior.
  • CI/docs tweaks: skip PR test workflow jobs on branch-deletion pushes; simplify actionlint step configuration and refresh related documentation text.

Reviewed changes

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Show a summary per file
FileDescription
WORKFLOW.mdUpdates shipped-input definition and operational guarantees to include Directory.Packages.props and explain the republish rationale.
repo-config/README.mdClarifies branch deletion behavior (repo setting off; explicit per-merge deletion instead).
repo-config/configure.shHardens ruleset lookup, adds jq_lacks, and improves secrets-check error reporting.
AGENTS.mdUpdates merge/release guidance to reflect dependency bumps now triggering publish.
.github/workflows/validate-task.ymlSimplifies workflow-lint step configuration for actionlint.
.github/workflows/test-pull-request.ymlSkips reusable-workflow jobs (and the status aggregator) on deleted-branch push events.
.github/workflows/publish-release.ymlAdds Directory.Packages.props to the shipped-input on.push.paths trigger and updates comments accordingly.

Comment threadrepo-config/configure.sh Outdated
Capture jq's exit code with `|| rc=$?` (a list is exempt from errexit)
so an exit-1 no-match returns 'lacks' rather than risking a `set -e`
abort outside a conditional, while still propagating a real jq error
(>1). Verified under `set -euo pipefail` for match / no-match /
jq-error. Follow-up to PR #211.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comment thread.github/workflows/publish-release.yml Outdated
Narrow the publish-release header comment - a package-version
(Directory.Packages.props) bump republishes; only a GitHub-Actions
Dependabot bump does not. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comment thread.github/workflows/test-pull-request.yml Outdated
WORKFLOW.md said validate/smoke-build run unconditionally, but they
carry a `!github.event.deleted` guard. Note the branch-deletion
exception in the architecture section, D1.1, and the 5A audit, and add
scenario S16. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comment thread.github/workflows/test-pull-request.yml Outdated
checkout/build fail -> fails. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comment threadWORKFLOW.md
Section 0's model-at-a-glance omitted package versions from the
shipped-input list (the glossary/D4.1 include them). Add it. Follow-up
to #211/#212.
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comments suppressed due to low confidence (1)

.github/workflows/validate-task.yml:73

  • The actionlint step no longer pins the underlying actionlint binary version (the version input was removed). Per raven-actions/actionlint docs, omitting version defaults to latest, which makes lint results non-reproducible and can cause CI to change behavior without a repo change. Pin version to a specific actionlint release and bump it intentionally alongside the action SHA.
 - name: Lint workflows step
uses: raven-actions/actionlint@3d39aea434753780c3b3d4a1a31c854b4dbf49d7 # v2.2.0

Comment thread.github/workflows/publish-release.yml Outdated
The on.push.paths inclusion list is below the header comment; change
'add a path above' to 'add a path to that list'. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated no new comments.

@ptr727
ptr727 merged commit db387ac into mainJun 29, 2026
11 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Promote develop to main: dependency-currency publish + configure.sh hardening by ptr727 · Pull Request #212 · ptr727/LanguageTags · GitHub
Skip to content

Promote develop to main: dependency-currency publish + configure.sh hardening - #212

Merged
ptr727 merged 7 commits into
mainfrom
develop
Jun 29, 2026
Merged

Promote develop to main: dependency-currency publish + configure.sh hardening#212
ptr727 merged 7 commits into
mainfrom
develop

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Promotes PR #211 from develop to main.

What lands on main

  • Dependency currency:Directory.Packages.props is now a shipped input, so a merged dependency bump republishes and the published package's declared dependencies stay current (a NuGet version can't be re-pushed, so there's no Docker-style refresh). GitHub-Actions bumps stay excluded. WORKFLOW.md/AGENTS.md updated.
  • configure.sh hardening:ruleset_id (error-distinction, jq --arg, pipefail-safe, per_page=100), jq_lacks (propagates real jq errors), check_secrets (surfaces gh's stderr, accurate comment).
  • repo-config README states the actual branch cleanup (auto-delete setting off to protect develop; merge-bot deletes bot branches with --delete-branch).

Standard promotion PR with review (no admin bypass). No library code change.

Keeps the push-self-publish model (correct for NuGet - there is no
Docker-style refresh, and a NuGet version can't be re-pushed) and closes
the stale-dependency window, plus brings repo-config in line with the
hardened canonical.
## Dependency currency
A NuGet package's declared dependencies only update when a new version
is published. With no scheduled rebuild possible, a merged dependency
bump must republish or the package keeps shipping old/vulnerable
dependency constraints. So **`Directory.Packages.props` is now a shipped
input**: a dependency bump on main/develop auto-publishes that branch,
keeping the package current. GitHub-Actions bumps stay excluded (they do
not ship in the package).
Trade-off (accepted): because versions are centrally managed, a
test/codegen dependency bump (e.g. `xunit.v3`) also republishes even
though it does not ship - cheap version churn in exchange for never
shipping a stale dependency. (The shipped library has effectively one
runtime dependency, `Microsoft.Extensions.Logging.Abstractions`.)
WORKFLOW.md (glossary, D4.1, D8.2, 5A audit, S11) and AGENTS.md updated
to match.
## repo-config hardening
`configure.sh` `ruleset_id` distinguishes an absent ruleset from a real
API error (lets gh surface its stderr; returns non-zero instead of a
silent `set -e` abort), uses `jq --arg`, selects the first match inside
jq (pipefail-safe), and pages the lookup (`per_page=100`). The
repo-config README states the actual branch cleanup (auto-delete off so
a `develop -> main` promotion does not delete `develop`; merged
bot/feature branches cleaned up manually). Task comments aligned to the
terse canonical form.
## Verification
actionlint, markdownlint, shellcheck, `bash -n` clean; EOL preserved.
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 29, 2026 00:57

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Promotes develop to main while updating the release trigger definition so dependency version bumps republish the NuGet package, and hardens repo-config/configure.sh plus a few CI/documentation adjustments.

Changes:

  • Treat Directory.Packages.props as a shipped input (docs + publish workflow path filter) so dependency bumps republish and keep declared dependencies current.
  • Harden repo-config/configure.sh around ruleset lookup, jq error handling, and secrets listing behavior.
  • CI/docs tweaks: skip PR test workflow jobs on branch-deletion pushes; simplify actionlint step configuration and refresh related documentation text.

Reviewed changes

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Show a summary per file
FileDescription
WORKFLOW.mdUpdates shipped-input definition and operational guarantees to include Directory.Packages.props and explain the republish rationale.
repo-config/README.mdClarifies branch deletion behavior (repo setting off; explicit per-merge deletion instead).
repo-config/configure.shHardens ruleset lookup, adds jq_lacks, and improves secrets-check error reporting.
AGENTS.mdUpdates merge/release guidance to reflect dependency bumps now triggering publish.
.github/workflows/validate-task.ymlSimplifies workflow-lint step configuration for actionlint.
.github/workflows/test-pull-request.ymlSkips reusable-workflow jobs (and the status aggregator) on deleted-branch push events.
.github/workflows/publish-release.ymlAdds Directory.Packages.props to the shipped-input on.push.paths trigger and updates comments accordingly.

Comment threadrepo-config/configure.sh Outdated
Capture jq's exit code with `|| rc=$?` (a list is exempt from errexit)
so an exit-1 no-match returns 'lacks' rather than risking a `set -e`
abort outside a conditional, while still propagating a real jq error
(>1). Verified under `set -euo pipefail` for match / no-match /
jq-error. Follow-up to PR #211.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comment thread.github/workflows/publish-release.yml Outdated
Narrow the publish-release header comment - a package-version
(Directory.Packages.props) bump republishes; only a GitHub-Actions
Dependabot bump does not. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comment thread.github/workflows/test-pull-request.yml Outdated
WORKFLOW.md said validate/smoke-build run unconditionally, but they
carry a `!github.event.deleted` guard. Note the branch-deletion
exception in the architecture section, D1.1, and the 5A audit, and add
scenario S16. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comment thread.github/workflows/test-pull-request.yml Outdated
checkout/build fail -> fails. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comment threadWORKFLOW.md
Section 0's model-at-a-glance omitted package versions from the
shipped-input list (the glossary/D4.1 include them). Add it. Follow-up
to #211/#212.
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comments suppressed due to low confidence (1)

.github/workflows/validate-task.yml:73

  • The actionlint step no longer pins the underlying actionlint binary version (the version input was removed). Per raven-actions/actionlint docs, omitting version defaults to latest, which makes lint results non-reproducible and can cause CI to change behavior without a repo change. Pin version to a specific actionlint release and bump it intentionally alongside the action SHA.
 - name: Lint workflows step
uses: raven-actions/actionlint@3d39aea434753780c3b3d4a1a31c854b4dbf49d7 # v2.2.0

Comment thread.github/workflows/publish-release.yml Outdated
The on.push.paths inclusion list is below the header comment; change
'add a path above' to 'add a path to that list'. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated no new comments.

@ptr727
ptr727 merged commit db387ac into mainJun 29, 2026
11 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); Promote develop to main: dependency-currency publish + configure.sh hardening by ptr727 · Pull Request #212 · ptr727/LanguageTags · GitHub
Skip to content

Promote develop to main: dependency-currency publish + configure.sh hardening - #212

Merged
ptr727 merged 7 commits into
mainfrom
develop
Jun 29, 2026
Merged

Promote develop to main: dependency-currency publish + configure.sh hardening#212
ptr727 merged 7 commits into
mainfrom
develop

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Promotes PR #211 from develop to main.

What lands on main

  • Dependency currency:Directory.Packages.props is now a shipped input, so a merged dependency bump republishes and the published package's declared dependencies stay current (a NuGet version can't be re-pushed, so there's no Docker-style refresh). GitHub-Actions bumps stay excluded. WORKFLOW.md/AGENTS.md updated.
  • configure.sh hardening:ruleset_id (error-distinction, jq --arg, pipefail-safe, per_page=100), jq_lacks (propagates real jq errors), check_secrets (surfaces gh's stderr, accurate comment).
  • repo-config README states the actual branch cleanup (auto-delete setting off to protect develop; merge-bot deletes bot branches with --delete-branch).

Standard promotion PR with review (no admin bypass). No library code change.

Keeps the push-self-publish model (correct for NuGet - there is no
Docker-style refresh, and a NuGet version can't be re-pushed) and closes
the stale-dependency window, plus brings repo-config in line with the
hardened canonical.
## Dependency currency
A NuGet package's declared dependencies only update when a new version
is published. With no scheduled rebuild possible, a merged dependency
bump must republish or the package keeps shipping old/vulnerable
dependency constraints. So **`Directory.Packages.props` is now a shipped
input**: a dependency bump on main/develop auto-publishes that branch,
keeping the package current. GitHub-Actions bumps stay excluded (they do
not ship in the package).
Trade-off (accepted): because versions are centrally managed, a
test/codegen dependency bump (e.g. `xunit.v3`) also republishes even
though it does not ship - cheap version churn in exchange for never
shipping a stale dependency. (The shipped library has effectively one
runtime dependency, `Microsoft.Extensions.Logging.Abstractions`.)
WORKFLOW.md (glossary, D4.1, D8.2, 5A audit, S11) and AGENTS.md updated
to match.
## repo-config hardening
`configure.sh` `ruleset_id` distinguishes an absent ruleset from a real
API error (lets gh surface its stderr; returns non-zero instead of a
silent `set -e` abort), uses `jq --arg`, selects the first match inside
jq (pipefail-safe), and pages the lookup (`per_page=100`). The
repo-config README states the actual branch cleanup (auto-delete off so
a `develop -> main` promotion does not delete `develop`; merged
bot/feature branches cleaned up manually). Task comments aligned to the
terse canonical form.
## Verification
actionlint, markdownlint, shellcheck, `bash -n` clean; EOL preserved.
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 29, 2026 00:57

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Promotes develop to main while updating the release trigger definition so dependency version bumps republish the NuGet package, and hardens repo-config/configure.sh plus a few CI/documentation adjustments.

Changes:

  • Treat Directory.Packages.props as a shipped input (docs + publish workflow path filter) so dependency bumps republish and keep declared dependencies current.
  • Harden repo-config/configure.sh around ruleset lookup, jq error handling, and secrets listing behavior.
  • CI/docs tweaks: skip PR test workflow jobs on branch-deletion pushes; simplify actionlint step configuration and refresh related documentation text.

Reviewed changes

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Show a summary per file
FileDescription
WORKFLOW.mdUpdates shipped-input definition and operational guarantees to include Directory.Packages.props and explain the republish rationale.
repo-config/README.mdClarifies branch deletion behavior (repo setting off; explicit per-merge deletion instead).
repo-config/configure.shHardens ruleset lookup, adds jq_lacks, and improves secrets-check error reporting.
AGENTS.mdUpdates merge/release guidance to reflect dependency bumps now triggering publish.
.github/workflows/validate-task.ymlSimplifies workflow-lint step configuration for actionlint.
.github/workflows/test-pull-request.ymlSkips reusable-workflow jobs (and the status aggregator) on deleted-branch push events.
.github/workflows/publish-release.ymlAdds Directory.Packages.props to the shipped-input on.push.paths trigger and updates comments accordingly.

Comment threadrepo-config/configure.sh Outdated
Capture jq's exit code with `|| rc=$?` (a list is exempt from errexit)
so an exit-1 no-match returns 'lacks' rather than risking a `set -e`
abort outside a conditional, while still propagating a real jq error
(>1). Verified under `set -euo pipefail` for match / no-match /
jq-error. Follow-up to PR #211.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comment thread.github/workflows/publish-release.yml Outdated
Narrow the publish-release header comment - a package-version
(Directory.Packages.props) bump republishes; only a GitHub-Actions
Dependabot bump does not. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comment thread.github/workflows/test-pull-request.yml Outdated
WORKFLOW.md said validate/smoke-build run unconditionally, but they
carry a `!github.event.deleted` guard. Note the branch-deletion
exception in the architecture section, D1.1, and the 5A audit, and add
scenario S16. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comment thread.github/workflows/test-pull-request.yml Outdated
checkout/build fail -> fails. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comment threadWORKFLOW.md
Section 0's model-at-a-glance omitted package versions from the
shipped-input list (the glossary/D4.1 include them). Add it. Follow-up
to #211/#212.
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.

Comments suppressed due to low confidence (1)

.github/workflows/validate-task.yml:73

  • The actionlint step no longer pins the underlying actionlint binary version (the version input was removed). Per raven-actions/actionlint docs, omitting version defaults to latest, which makes lint results non-reproducible and can cause CI to change behavior without a repo change. Pin version to a specific actionlint release and bump it intentionally alongside the action SHA.
 - name: Lint workflows step
uses: raven-actions/actionlint@3d39aea434753780c3b3d4a1a31c854b4dbf49d7 # v2.2.0

Comment thread.github/workflows/publish-release.yml Outdated
The on.push.paths inclusion list is below the header comment; change
'add a path above' to 'add a path to that list'. Follow-up to #211/#212.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated no new comments.

@ptr727
ptr727 merged commit db387ac into mainJun 29, 2026
11 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727