Release: two-phase dual-publish release model - #322

Closed
ptr727 wants to merge 32 commits into
mainfrom
release/dualpublish
Closed

Release: two-phase dual-publish release model#322
ptr727 wants to merge 32 commits into
mainfrom
release/dualpublish

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Summary

Release the two-phase dual-publish model to main. This branch is main merged with develop (the squash from #320), with the one-time old→new structural conflicts resolved in develop's favour and the max dependency/tool versions taken so main's newer Dependabot bumps are not regressed.

Supersedes #321 (the direct developmain PR, which had inherent merge conflicts from the old merge base). The main ruleset has been updated to the new model: required check is now Check pull request workflow status, merge-commit only, strict/up-to-date off, linear-history requirement dropped.

Dependency reconciliation (max of develop/main)

Package / toolVersion
Microsoft.SourceLink.GitHub10.0.201
Serilog4.3.1
Microsoft.NET.Test.Sdk18.4.0
xunit.analyzers1.27.0
csharpier (tool)1.2.6
husky (tool)0.9.1

Everything else is exactly the develop tree (see #320 for the full change description). Net diff vs develop is only the six version bumps above.

Maintainer follow-ups (after merge)

  • Add CODEGEN_APP_CLIENT_ID / CODEGEN_APP_PRIVATE_KEY (GitHub App) to both Actions and Dependabot secret stores for the merge-bot.
  • Update the develop ruleset's required check to Check pull request workflow status (the main ruleset is already updated).
  • Bump develop's Directory.Packages.props / tools to match so the branches stay in sync (or let Dependabot do it).
  • Trigger the first publish via publish-release.yml → Run workflow once secrets are in place.

🤖 Generated with Claude Code

dependabotBotand others added 30 commits August 19, 2025 20:51
Bumps csharpier from 1.1.1 to 1.1.2
Bumps xunit.analyzers from 1.23.0 to 1.24.0
Bumps xunit.runner.visualstudio from 3.1.3 to 3.1.4
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.1.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
- dependency-name: xunit.analyzers
dependency-version: 1.24.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
- dependency-name: xunit.runner.visualstudio
dependency-version: 3.1.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-0259308462
Bump the nuget-deps group with 3 updates
Bumps xunit.runner.visualstudio from 3.1.4 to 3.1.5
---
updated-dependencies:
- dependency-name: xunit.runner.visualstudio
dependency-version: 3.1.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…evelop/nuget-deps-6aadeae1b1
Bump the nuget-deps group with 1 update
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-39349b7924
Bump csharpier from 1.1.2 to 1.2.1
---
updated-dependencies:
- dependency-name: Serilog.Sinks.Console
dependency-version: 6.1.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…nuget-deps-602f419b37
Bump Serilog.Sinks.Console from 6.0.0 to 6.1.1
Bumps csharpier from 1.2.1 to 1.2.3
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-1689e99d0a
Bump the nuget-deps group with 1 update
Bumps the actions-deps group with 2 updates in the / directory: [actions/setup-dotnet](https://github.com/actions/setup-dotnet) and [actions/checkout](https://github.com/actions/checkout).
Updates `actions/setup-dotnet` from 4 to 5
- [Release notes](https://github.com/actions/setup-dotnet/releases)
- [Commits](actions/setup-dotnet@v4...v5)
Updates `actions/checkout` from 5 to 6
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v5...v6)
---
updated-dependencies:
- dependency-name: actions/setup-dotnet
dependency-version: '5'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
- dependency-name: actions/checkout
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps csharpier from 1.2.3 to 1.2.4
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-133b2bc611
Bump the nuget-deps group with 1 update
Bumps csharpier from 1.2.4 to 1.2.5
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-262ca43251
Bump the nuget-deps group with 1 update
* Initial plan
* Add using statement and simplify CallerMemberName attributes
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
* Initial plan
* Make HttpClient timeout configurable via TimeoutSeconds property
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Initial plan
* Replace redundant ToString() with string interpolation in FileExAsyncTests
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
* Initial plan
* Replace explicit ToString() calls with string interpolation
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
…304)
Bumps the actions-deps group with 1 update: [dependabot/fetch-metadata](https://github.com/dependabot/fetch-metadata).
Updates `dependabot/fetch-metadata` from 2 to 3
- [Release notes](https://github.com/dependabot/fetch-metadata/releases)
- [Commits](dependabot/fetch-metadata@v2...v3)
---
updated-dependencies:
- dependency-name: dependabot/fetch-metadata
dependency-version: '3'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
ptr727 added 2 commits June 4, 2026 18:28
* Convert to two-phase dual-publish release model
Replace publish-on-push with the ProjectTemplate/LanguageTags two-phase
model: PRs smoke-test only, and publish-release.yml publishes both branches
on a weekly schedule (Mon 02:00 UTC) or manual dispatch, with idempotent
no-op republish. Adopt the reusable workflow set (get-version,
build-nugetlibrary, build-release, build-datebadge), a branch-aware
Dependabot merge-bot, Central Package Management, and an AGENTS.md tracking
the template. NuGet.org-only (drop GitHub Packages); no Docker/exe/PyPI/codegen.
Reconcile the template's strict analyzers (AnalysisMode All +
TreatWarningsAsErrors) with the brownfield library by relaxing specific
rules in .editorconfig and IL3058 via NoWarn, all documented.
* Normalize line endings to .editorconfig; fix husky hook
Convert the workflow YAML, dependabot.yml, and AGENTS.md (added LF) to CRLF
per .editorconfig, and make .husky/pre-commit LF + executable so its shebang
execs on Linux/WSL. Add an .editorconfig rule pinning the hook to LF.
* Quote "$GITHUB_OUTPUT" in date-badge task
Resolve the one-time old->new structural conflicts in develop's favour
(new reusable workflows, CPM, AGENTS.md, reformatting) and take the max
dependency/tool versions so main's newer Dependabot bumps are not regressed
(SourceLink 10.0.201, Serilog 4.3.1, Microsoft.NET.Test.Sdk 18.4.0,
xunit.analyzers 1.27.0, csharpier 1.2.6, husky 0.9.1).
CopilotAI review requested due to automatic review settings June 5, 2026 02:26

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Promotes the repository to the two-phase, dual-publish release model on main, aligning CI/CD, dependency management, and repo process documentation with the template-driven structure introduced on develop (with select version reconciliations to avoid regressing Dependabot bumps).

Changes:

  • Introduces the new CI/CD workflow set (PR smoke-test + scheduled/manual publish + Dependabot merge-bot) and removes the legacy publish + dependabot automerge workflows.
  • Switches to Central Package Management (Directory.Build.props + Directory.Packages.props) and updates project files accordingly (incl. IL3058 suppression for AOT projects).
  • Adds/updates repo process & configuration files (AGENTS.md, .editorconfig husky LF rule, .gitignore, README badge, solution items).

Reviewed changes

Copilot reviewed 38 out of 40 changed files in this pull request and generated 4 comments.

Show a summary per file
FileDescription
UtilitiesTests/UtilitiesTests.csprojMoves package versions to central management.
UtilitiesTests/UtilitiesTests.csRemoves now-redundant usings (implicit usings).
UtilitiesTests/StringHistoryTests.csRemoves now-redundant usings.
UtilitiesTests/StringCompressionTests.csRemoves now-redundant usings.
UtilitiesTests/StringCompressionAsyncTests.csRemoves now-redundant usings.
UtilitiesTests/FileExAsyncTests.csRemoves now-redundant usings.
UtilitiesTests/ExtensionsTests.csAdjusts null-handling tests; trims usings.
UtilitiesTests/DownloadTests.csRemoves now-redundant usings.
UtilitiesTests/DownloadAsyncTests.csRemoves now-redundant usings.
UtilitiesTests/ConsoleTests.csRemoves now-redundant usings.
Utilities/Utilities.csprojCentralizes TF/analyzers; suppresses IL3058; packable.
Utilities/StringHistory.csRemoves now-redundant usings.
Utilities/StringCompression.csRemoves now-redundant usings.
Utilities/Format.csRemoves now-redundant usings.
Utilities/FileExOptions.csRemoves now-redundant usings.
Utilities/FileEx.csRemoves now-redundant usings.
Utilities/Extensions.csRemoves now-redundant usings.
Utilities/Download.csRemoves now-redundant usings.
Utilities/ConsoleEx.csRemoves now-redundant usings.
Utilities/CommandLineEx.csRemoves now-redundant usings.
Utilities.slnxAdds new solution items + workflow files.
Sandbox/Sandbox.csprojCentralizes packages; suppresses IL3058.
Sandbox/Program.csMinor cleanup (AppContext usage).
README.mdUpdates workflow status badge to new workflow.
Directory.Packages.propsAdds centralized package versions.
Directory.Build.propsAdds shared build properties/analyzer strictness.
AGENTS.mdDocuments branching/release/workflow conventions.
.husky/pre-commitNormalizes hook file (LF/shebang handling).
.gitignoreIgnores .artifacts output directory.
.github/workflows/test-pull-request.ymlNew PR test/smoke build workflow + required-check aggregator.
.github/workflows/publish-release.ymlNew scheduled/manual publisher with two-phase gating.
.github/workflows/merge-bot-pull-request.ymlNew Dependabot merge-bot using app token + branch-aware merge method.
.github/workflows/get-version-task.ymlNew reusable NBGV version task.
.github/workflows/build-release-task.ymlNew orchestrator reusable workflow (build + optional publish).
.github/workflows/build-nugetlibrary-task.ymlNew reusable NuGet build/push task with artifacts.
.github/workflows/build-datebadge-task.ymlNew reusable BYOB date badge task.
.github/workflows/DependabotAutoMerge.ymlRemoves legacy Dependabot auto-merge workflow.
.github/workflows/BuildPublishPipeline.ymlRemoves legacy publish-on-push workflow.
.github/dependabot.ymlDuplicates ecosystems per-branch (main/develop).
.editorconfigAdds Husky hook LF rule + analyzer relaxations.

Comment threadUtilitiesTests/ExtensionsTests.cs
Comment threadUtilitiesTests/ExtensionsTests.cs
Comment threadUtilitiesTests/ExtensionsTests.cs
Comment thread.github/workflows/build-datebadge-task.yml
ptr727 added a commit that referenced this pull request Jun 5, 2026
## Summary
Land the two-phase dual-publish model on `main`, with **fully signed &
GitHub-verified history**. This is `main` merged with `develop`
(`0f1616d`), the one-time old→new structural conflicts resolved in
**develop's favour**, and the **max dependency/tool versions** taken so
`main`'s newer Dependabot bumps are not regressed.
All introduced commits are committer = `Pieter Viljoen
<ptr727@users.noreply.github.com>` and verified, satisfying
`required_signatures` (supersedes #322/#323, which carried unverifiable
web-flow-committed history).
### Dependency reconciliation (max of develop/main)
| Package / tool | Version |
| --- | --- |
| Microsoft.SourceLink.GitHub | 10.0.201 |
| Serilog | 4.3.1 |
| Microsoft.NET.Test.Sdk | 18.4.0 |
| xunit.analyzers | 1.27.0 |
| csharpier (tool) | 1.2.6 |
| husky (tool) | 0.9.1 |
Net diff vs `develop` is only the six version bumps above. See #320 for
the full change description.
## Maintainer follow-ups (after merge)
- Add `CODEGEN_APP_CLIENT_ID` / `CODEGEN_APP_PRIVATE_KEY` (GitHub App)
to **both** Actions and Dependabot secret stores for the merge-bot.
- Let Dependabot bring `develop`'s deps up to match (or open a small
sync PR).
- Kick off the first publish via **Actions → publish-release.yml → Run
workflow** once secrets are in.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
@ptr727ptr727 closed this Jun 5, 2026
@ptr727
ptr727 deleted the release/dualpublish branch June 5, 2026 13:13
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Release: two-phase dual-publish release model - #322

Closed
ptr727 wants to merge 32 commits into
mainfrom
release/dualpublish
Closed

Release: two-phase dual-publish release model#322
ptr727 wants to merge 32 commits into
mainfrom
release/dualpublish

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Summary

Release the two-phase dual-publish model to main. This branch is main merged with develop (the squash from #320), with the one-time old→new structural conflicts resolved in develop's favour and the max dependency/tool versions taken so main's newer Dependabot bumps are not regressed.

Supersedes #321 (the direct developmain PR, which had inherent merge conflicts from the old merge base). The main ruleset has been updated to the new model: required check is now Check pull request workflow status, merge-commit only, strict/up-to-date off, linear-history requirement dropped.

Dependency reconciliation (max of develop/main)

Package / toolVersion
Microsoft.SourceLink.GitHub10.0.201
Serilog4.3.1
Microsoft.NET.Test.Sdk18.4.0
xunit.analyzers1.27.0
csharpier (tool)1.2.6
husky (tool)0.9.1

Everything else is exactly the develop tree (see #320 for the full change description). Net diff vs develop is only the six version bumps above.

Maintainer follow-ups (after merge)

  • Add CODEGEN_APP_CLIENT_ID / CODEGEN_APP_PRIVATE_KEY (GitHub App) to both Actions and Dependabot secret stores for the merge-bot.
  • Update the develop ruleset's required check to Check pull request workflow status (the main ruleset is already updated).
  • Bump develop's Directory.Packages.props / tools to match so the branches stay in sync (or let Dependabot do it).
  • Trigger the first publish via publish-release.yml → Run workflow once secrets are in place.

🤖 Generated with Claude Code

dependabotBotand others added 30 commits August 19, 2025 20:51
Bumps csharpier from 1.1.1 to 1.1.2
Bumps xunit.analyzers from 1.23.0 to 1.24.0
Bumps xunit.runner.visualstudio from 3.1.3 to 3.1.4
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.1.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
- dependency-name: xunit.analyzers
dependency-version: 1.24.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
- dependency-name: xunit.runner.visualstudio
dependency-version: 3.1.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-0259308462
Bump the nuget-deps group with 3 updates
Bumps xunit.runner.visualstudio from 3.1.4 to 3.1.5
---
updated-dependencies:
- dependency-name: xunit.runner.visualstudio
dependency-version: 3.1.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…evelop/nuget-deps-6aadeae1b1
Bump the nuget-deps group with 1 update
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-39349b7924
Bump csharpier from 1.1.2 to 1.2.1
---
updated-dependencies:
- dependency-name: Serilog.Sinks.Console
dependency-version: 6.1.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…nuget-deps-602f419b37
Bump Serilog.Sinks.Console from 6.0.0 to 6.1.1
Bumps csharpier from 1.2.1 to 1.2.3
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-1689e99d0a
Bump the nuget-deps group with 1 update
Bumps the actions-deps group with 2 updates in the / directory: [actions/setup-dotnet](https://github.com/actions/setup-dotnet) and [actions/checkout](https://github.com/actions/checkout).
Updates `actions/setup-dotnet` from 4 to 5
- [Release notes](https://github.com/actions/setup-dotnet/releases)
- [Commits](actions/setup-dotnet@v4...v5)
Updates `actions/checkout` from 5 to 6
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v5...v6)
---
updated-dependencies:
- dependency-name: actions/setup-dotnet
dependency-version: '5'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
- dependency-name: actions/checkout
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps csharpier from 1.2.3 to 1.2.4
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-133b2bc611
Bump the nuget-deps group with 1 update
Bumps csharpier from 1.2.4 to 1.2.5
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-262ca43251
Bump the nuget-deps group with 1 update
* Initial plan
* Add using statement and simplify CallerMemberName attributes
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
* Initial plan
* Make HttpClient timeout configurable via TimeoutSeconds property
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Initial plan
* Replace redundant ToString() with string interpolation in FileExAsyncTests
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
* Initial plan
* Replace explicit ToString() calls with string interpolation
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
…304)
Bumps the actions-deps group with 1 update: [dependabot/fetch-metadata](https://github.com/dependabot/fetch-metadata).
Updates `dependabot/fetch-metadata` from 2 to 3
- [Release notes](https://github.com/dependabot/fetch-metadata/releases)
- [Commits](dependabot/fetch-metadata@v2...v3)
---
updated-dependencies:
- dependency-name: dependabot/fetch-metadata
dependency-version: '3'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
ptr727 added 2 commits June 4, 2026 18:28
* Convert to two-phase dual-publish release model
Replace publish-on-push with the ProjectTemplate/LanguageTags two-phase
model: PRs smoke-test only, and publish-release.yml publishes both branches
on a weekly schedule (Mon 02:00 UTC) or manual dispatch, with idempotent
no-op republish. Adopt the reusable workflow set (get-version,
build-nugetlibrary, build-release, build-datebadge), a branch-aware
Dependabot merge-bot, Central Package Management, and an AGENTS.md tracking
the template. NuGet.org-only (drop GitHub Packages); no Docker/exe/PyPI/codegen.
Reconcile the template's strict analyzers (AnalysisMode All +
TreatWarningsAsErrors) with the brownfield library by relaxing specific
rules in .editorconfig and IL3058 via NoWarn, all documented.
* Normalize line endings to .editorconfig; fix husky hook
Convert the workflow YAML, dependabot.yml, and AGENTS.md (added LF) to CRLF
per .editorconfig, and make .husky/pre-commit LF + executable so its shebang
execs on Linux/WSL. Add an .editorconfig rule pinning the hook to LF.
* Quote "$GITHUB_OUTPUT" in date-badge task
Resolve the one-time old->new structural conflicts in develop's favour
(new reusable workflows, CPM, AGENTS.md, reformatting) and take the max
dependency/tool versions so main's newer Dependabot bumps are not regressed
(SourceLink 10.0.201, Serilog 4.3.1, Microsoft.NET.Test.Sdk 18.4.0,
xunit.analyzers 1.27.0, csharpier 1.2.6, husky 0.9.1).
CopilotAI review requested due to automatic review settings June 5, 2026 02:26

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Promotes the repository to the two-phase, dual-publish release model on main, aligning CI/CD, dependency management, and repo process documentation with the template-driven structure introduced on develop (with select version reconciliations to avoid regressing Dependabot bumps).

Changes:

  • Introduces the new CI/CD workflow set (PR smoke-test + scheduled/manual publish + Dependabot merge-bot) and removes the legacy publish + dependabot automerge workflows.
  • Switches to Central Package Management (Directory.Build.props + Directory.Packages.props) and updates project files accordingly (incl. IL3058 suppression for AOT projects).
  • Adds/updates repo process & configuration files (AGENTS.md, .editorconfig husky LF rule, .gitignore, README badge, solution items).

Reviewed changes

Copilot reviewed 38 out of 40 changed files in this pull request and generated 4 comments.

Show a summary per file
FileDescription
UtilitiesTests/UtilitiesTests.csprojMoves package versions to central management.
UtilitiesTests/UtilitiesTests.csRemoves now-redundant usings (implicit usings).
UtilitiesTests/StringHistoryTests.csRemoves now-redundant usings.
UtilitiesTests/StringCompressionTests.csRemoves now-redundant usings.
UtilitiesTests/StringCompressionAsyncTests.csRemoves now-redundant usings.
UtilitiesTests/FileExAsyncTests.csRemoves now-redundant usings.
UtilitiesTests/ExtensionsTests.csAdjusts null-handling tests; trims usings.
UtilitiesTests/DownloadTests.csRemoves now-redundant usings.
UtilitiesTests/DownloadAsyncTests.csRemoves now-redundant usings.
UtilitiesTests/ConsoleTests.csRemoves now-redundant usings.
Utilities/Utilities.csprojCentralizes TF/analyzers; suppresses IL3058; packable.
Utilities/StringHistory.csRemoves now-redundant usings.
Utilities/StringCompression.csRemoves now-redundant usings.
Utilities/Format.csRemoves now-redundant usings.
Utilities/FileExOptions.csRemoves now-redundant usings.
Utilities/FileEx.csRemoves now-redundant usings.
Utilities/Extensions.csRemoves now-redundant usings.
Utilities/Download.csRemoves now-redundant usings.
Utilities/ConsoleEx.csRemoves now-redundant usings.
Utilities/CommandLineEx.csRemoves now-redundant usings.
Utilities.slnxAdds new solution items + workflow files.
Sandbox/Sandbox.csprojCentralizes packages; suppresses IL3058.
Sandbox/Program.csMinor cleanup (AppContext usage).
README.mdUpdates workflow status badge to new workflow.
Directory.Packages.propsAdds centralized package versions.
Directory.Build.propsAdds shared build properties/analyzer strictness.
AGENTS.mdDocuments branching/release/workflow conventions.
.husky/pre-commitNormalizes hook file (LF/shebang handling).
.gitignoreIgnores .artifacts output directory.
.github/workflows/test-pull-request.ymlNew PR test/smoke build workflow + required-check aggregator.
.github/workflows/publish-release.ymlNew scheduled/manual publisher with two-phase gating.
.github/workflows/merge-bot-pull-request.ymlNew Dependabot merge-bot using app token + branch-aware merge method.
.github/workflows/get-version-task.ymlNew reusable NBGV version task.
.github/workflows/build-release-task.ymlNew orchestrator reusable workflow (build + optional publish).
.github/workflows/build-nugetlibrary-task.ymlNew reusable NuGet build/push task with artifacts.
.github/workflows/build-datebadge-task.ymlNew reusable BYOB date badge task.
.github/workflows/DependabotAutoMerge.ymlRemoves legacy Dependabot auto-merge workflow.
.github/workflows/BuildPublishPipeline.ymlRemoves legacy publish-on-push workflow.
.github/dependabot.ymlDuplicates ecosystems per-branch (main/develop).
.editorconfigAdds Husky hook LF rule + analyzer relaxations.

Comment threadUtilitiesTests/ExtensionsTests.cs
Comment threadUtilitiesTests/ExtensionsTests.cs
Comment threadUtilitiesTests/ExtensionsTests.cs
Comment thread.github/workflows/build-datebadge-task.yml
ptr727 added a commit that referenced this pull request Jun 5, 2026
## Summary
Land the two-phase dual-publish model on `main`, with **fully signed &
GitHub-verified history**. This is `main` merged with `develop`
(`0f1616d`), the one-time old→new structural conflicts resolved in
**develop's favour**, and the **max dependency/tool versions** taken so
`main`'s newer Dependabot bumps are not regressed.
All introduced commits are committer = `Pieter Viljoen
<ptr727@users.noreply.github.com>` and verified, satisfying
`required_signatures` (supersedes #322/#323, which carried unverifiable
web-flow-committed history).
### Dependency reconciliation (max of develop/main)
| Package / tool | Version |
| --- | --- |
| Microsoft.SourceLink.GitHub | 10.0.201 |
| Serilog | 4.3.1 |
| Microsoft.NET.Test.Sdk | 18.4.0 |
| xunit.analyzers | 1.27.0 |
| csharpier (tool) | 1.2.6 |
| husky (tool) | 0.9.1 |
Net diff vs `develop` is only the six version bumps above. See #320 for
the full change description.
## Maintainer follow-ups (after merge)
- Add `CODEGEN_APP_CLIENT_ID` / `CODEGEN_APP_PRIVATE_KEY` (GitHub App)
to **both** Actions and Dependabot secret stores for the merge-bot.
- Let Dependabot bring `develop`'s deps up to match (or open a small
sync PR).
- Kick off the first publish via **Actions → publish-release.yml → Run
workflow** once secrets are in.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
@ptr727ptr727 closed this Jun 5, 2026
@ptr727
ptr727 deleted the release/dualpublish branch June 5, 2026 13:13
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Release: two-phase dual-publish release model - #322

Closed
ptr727 wants to merge 32 commits into
mainfrom
release/dualpublish
Closed

Release: two-phase dual-publish release model#322
ptr727 wants to merge 32 commits into
mainfrom
release/dualpublish

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Summary

Release the two-phase dual-publish model to main. This branch is main merged with develop (the squash from #320), with the one-time old→new structural conflicts resolved in develop's favour and the max dependency/tool versions taken so main's newer Dependabot bumps are not regressed.

Supersedes #321 (the direct developmain PR, which had inherent merge conflicts from the old merge base). The main ruleset has been updated to the new model: required check is now Check pull request workflow status, merge-commit only, strict/up-to-date off, linear-history requirement dropped.

Dependency reconciliation (max of develop/main)

Package / toolVersion
Microsoft.SourceLink.GitHub10.0.201
Serilog4.3.1
Microsoft.NET.Test.Sdk18.4.0
xunit.analyzers1.27.0
csharpier (tool)1.2.6
husky (tool)0.9.1

Everything else is exactly the develop tree (see #320 for the full change description). Net diff vs develop is only the six version bumps above.

Maintainer follow-ups (after merge)

  • Add CODEGEN_APP_CLIENT_ID / CODEGEN_APP_PRIVATE_KEY (GitHub App) to both Actions and Dependabot secret stores for the merge-bot.
  • Update the develop ruleset's required check to Check pull request workflow status (the main ruleset is already updated).
  • Bump develop's Directory.Packages.props / tools to match so the branches stay in sync (or let Dependabot do it).
  • Trigger the first publish via publish-release.yml → Run workflow once secrets are in place.

🤖 Generated with Claude Code

dependabotBotand others added 30 commits August 19, 2025 20:51
Bumps csharpier from 1.1.1 to 1.1.2
Bumps xunit.analyzers from 1.23.0 to 1.24.0
Bumps xunit.runner.visualstudio from 3.1.3 to 3.1.4
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.1.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
- dependency-name: xunit.analyzers
dependency-version: 1.24.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
- dependency-name: xunit.runner.visualstudio
dependency-version: 3.1.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-0259308462
Bump the nuget-deps group with 3 updates
Bumps xunit.runner.visualstudio from 3.1.4 to 3.1.5
---
updated-dependencies:
- dependency-name: xunit.runner.visualstudio
dependency-version: 3.1.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…evelop/nuget-deps-6aadeae1b1
Bump the nuget-deps group with 1 update
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-39349b7924
Bump csharpier from 1.1.2 to 1.2.1
---
updated-dependencies:
- dependency-name: Serilog.Sinks.Console
dependency-version: 6.1.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…nuget-deps-602f419b37
Bump Serilog.Sinks.Console from 6.0.0 to 6.1.1
Bumps csharpier from 1.2.1 to 1.2.3
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-1689e99d0a
Bump the nuget-deps group with 1 update
Bumps the actions-deps group with 2 updates in the / directory: [actions/setup-dotnet](https://github.com/actions/setup-dotnet) and [actions/checkout](https://github.com/actions/checkout).
Updates `actions/setup-dotnet` from 4 to 5
- [Release notes](https://github.com/actions/setup-dotnet/releases)
- [Commits](actions/setup-dotnet@v4...v5)
Updates `actions/checkout` from 5 to 6
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v5...v6)
---
updated-dependencies:
- dependency-name: actions/setup-dotnet
dependency-version: '5'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
- dependency-name: actions/checkout
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps csharpier from 1.2.3 to 1.2.4
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-133b2bc611
Bump the nuget-deps group with 1 update
Bumps csharpier from 1.2.4 to 1.2.5
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-262ca43251
Bump the nuget-deps group with 1 update
* Initial plan
* Add using statement and simplify CallerMemberName attributes
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
* Initial plan
* Make HttpClient timeout configurable via TimeoutSeconds property
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Initial plan
* Replace redundant ToString() with string interpolation in FileExAsyncTests
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
* Initial plan
* Replace explicit ToString() calls with string interpolation
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
…304)
Bumps the actions-deps group with 1 update: [dependabot/fetch-metadata](https://github.com/dependabot/fetch-metadata).
Updates `dependabot/fetch-metadata` from 2 to 3
- [Release notes](https://github.com/dependabot/fetch-metadata/releases)
- [Commits](dependabot/fetch-metadata@v2...v3)
---
updated-dependencies:
- dependency-name: dependabot/fetch-metadata
dependency-version: '3'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
ptr727 added 2 commits June 4, 2026 18:28
* Convert to two-phase dual-publish release model
Replace publish-on-push with the ProjectTemplate/LanguageTags two-phase
model: PRs smoke-test only, and publish-release.yml publishes both branches
on a weekly schedule (Mon 02:00 UTC) or manual dispatch, with idempotent
no-op republish. Adopt the reusable workflow set (get-version,
build-nugetlibrary, build-release, build-datebadge), a branch-aware
Dependabot merge-bot, Central Package Management, and an AGENTS.md tracking
the template. NuGet.org-only (drop GitHub Packages); no Docker/exe/PyPI/codegen.
Reconcile the template's strict analyzers (AnalysisMode All +
TreatWarningsAsErrors) with the brownfield library by relaxing specific
rules in .editorconfig and IL3058 via NoWarn, all documented.
* Normalize line endings to .editorconfig; fix husky hook
Convert the workflow YAML, dependabot.yml, and AGENTS.md (added LF) to CRLF
per .editorconfig, and make .husky/pre-commit LF + executable so its shebang
execs on Linux/WSL. Add an .editorconfig rule pinning the hook to LF.
* Quote "$GITHUB_OUTPUT" in date-badge task
Resolve the one-time old->new structural conflicts in develop's favour
(new reusable workflows, CPM, AGENTS.md, reformatting) and take the max
dependency/tool versions so main's newer Dependabot bumps are not regressed
(SourceLink 10.0.201, Serilog 4.3.1, Microsoft.NET.Test.Sdk 18.4.0,
xunit.analyzers 1.27.0, csharpier 1.2.6, husky 0.9.1).
CopilotAI review requested due to automatic review settings June 5, 2026 02:26

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Promotes the repository to the two-phase, dual-publish release model on main, aligning CI/CD, dependency management, and repo process documentation with the template-driven structure introduced on develop (with select version reconciliations to avoid regressing Dependabot bumps).

Changes:

  • Introduces the new CI/CD workflow set (PR smoke-test + scheduled/manual publish + Dependabot merge-bot) and removes the legacy publish + dependabot automerge workflows.
  • Switches to Central Package Management (Directory.Build.props + Directory.Packages.props) and updates project files accordingly (incl. IL3058 suppression for AOT projects).
  • Adds/updates repo process & configuration files (AGENTS.md, .editorconfig husky LF rule, .gitignore, README badge, solution items).

Reviewed changes

Copilot reviewed 38 out of 40 changed files in this pull request and generated 4 comments.

Show a summary per file
FileDescription
UtilitiesTests/UtilitiesTests.csprojMoves package versions to central management.
UtilitiesTests/UtilitiesTests.csRemoves now-redundant usings (implicit usings).
UtilitiesTests/StringHistoryTests.csRemoves now-redundant usings.
UtilitiesTests/StringCompressionTests.csRemoves now-redundant usings.
UtilitiesTests/StringCompressionAsyncTests.csRemoves now-redundant usings.
UtilitiesTests/FileExAsyncTests.csRemoves now-redundant usings.
UtilitiesTests/ExtensionsTests.csAdjusts null-handling tests; trims usings.
UtilitiesTests/DownloadTests.csRemoves now-redundant usings.
UtilitiesTests/DownloadAsyncTests.csRemoves now-redundant usings.
UtilitiesTests/ConsoleTests.csRemoves now-redundant usings.
Utilities/Utilities.csprojCentralizes TF/analyzers; suppresses IL3058; packable.
Utilities/StringHistory.csRemoves now-redundant usings.
Utilities/StringCompression.csRemoves now-redundant usings.
Utilities/Format.csRemoves now-redundant usings.
Utilities/FileExOptions.csRemoves now-redundant usings.
Utilities/FileEx.csRemoves now-redundant usings.
Utilities/Extensions.csRemoves now-redundant usings.
Utilities/Download.csRemoves now-redundant usings.
Utilities/ConsoleEx.csRemoves now-redundant usings.
Utilities/CommandLineEx.csRemoves now-redundant usings.
Utilities.slnxAdds new solution items + workflow files.
Sandbox/Sandbox.csprojCentralizes packages; suppresses IL3058.
Sandbox/Program.csMinor cleanup (AppContext usage).
README.mdUpdates workflow status badge to new workflow.
Directory.Packages.propsAdds centralized package versions.
Directory.Build.propsAdds shared build properties/analyzer strictness.
AGENTS.mdDocuments branching/release/workflow conventions.
.husky/pre-commitNormalizes hook file (LF/shebang handling).
.gitignoreIgnores .artifacts output directory.
.github/workflows/test-pull-request.ymlNew PR test/smoke build workflow + required-check aggregator.
.github/workflows/publish-release.ymlNew scheduled/manual publisher with two-phase gating.
.github/workflows/merge-bot-pull-request.ymlNew Dependabot merge-bot using app token + branch-aware merge method.
.github/workflows/get-version-task.ymlNew reusable NBGV version task.
.github/workflows/build-release-task.ymlNew orchestrator reusable workflow (build + optional publish).
.github/workflows/build-nugetlibrary-task.ymlNew reusable NuGet build/push task with artifacts.
.github/workflows/build-datebadge-task.ymlNew reusable BYOB date badge task.
.github/workflows/DependabotAutoMerge.ymlRemoves legacy Dependabot auto-merge workflow.
.github/workflows/BuildPublishPipeline.ymlRemoves legacy publish-on-push workflow.
.github/dependabot.ymlDuplicates ecosystems per-branch (main/develop).
.editorconfigAdds Husky hook LF rule + analyzer relaxations.

Comment threadUtilitiesTests/ExtensionsTests.cs
Comment threadUtilitiesTests/ExtensionsTests.cs
Comment threadUtilitiesTests/ExtensionsTests.cs
Comment thread.github/workflows/build-datebadge-task.yml
ptr727 added a commit that referenced this pull request Jun 5, 2026
## Summary
Land the two-phase dual-publish model on `main`, with **fully signed &
GitHub-verified history**. This is `main` merged with `develop`
(`0f1616d`), the one-time old→new structural conflicts resolved in
**develop's favour**, and the **max dependency/tool versions** taken so
`main`'s newer Dependabot bumps are not regressed.
All introduced commits are committer = `Pieter Viljoen
<ptr727@users.noreply.github.com>` and verified, satisfying
`required_signatures` (supersedes #322/#323, which carried unverifiable
web-flow-committed history).
### Dependency reconciliation (max of develop/main)
| Package / tool | Version |
| --- | --- |
| Microsoft.SourceLink.GitHub | 10.0.201 |
| Serilog | 4.3.1 |
| Microsoft.NET.Test.Sdk | 18.4.0 |
| xunit.analyzers | 1.27.0 |
| csharpier (tool) | 1.2.6 |
| husky (tool) | 0.9.1 |
Net diff vs `develop` is only the six version bumps above. See #320 for
the full change description.
## Maintainer follow-ups (after merge)
- Add `CODEGEN_APP_CLIENT_ID` / `CODEGEN_APP_PRIVATE_KEY` (GitHub App)
to **both** Actions and Dependabot secret stores for the merge-bot.
- Let Dependabot bring `develop`'s deps up to match (or open a small
sync PR).
- Kick off the first publish via **Actions → publish-release.yml → Run
workflow** once secrets are in.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
@ptr727ptr727 closed this Jun 5, 2026
@ptr727
ptr727 deleted the release/dualpublish branch June 5, 2026 13:13
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Release: two-phase dual-publish release model - #322

Closed
ptr727 wants to merge 32 commits into
mainfrom
release/dualpublish
Closed

Release: two-phase dual-publish release model#322
ptr727 wants to merge 32 commits into
mainfrom
release/dualpublish

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Summary

Release the two-phase dual-publish model to main. This branch is main merged with develop (the squash from #320), with the one-time old→new structural conflicts resolved in develop's favour and the max dependency/tool versions taken so main's newer Dependabot bumps are not regressed.

Supersedes #321 (the direct developmain PR, which had inherent merge conflicts from the old merge base). The main ruleset has been updated to the new model: required check is now Check pull request workflow status, merge-commit only, strict/up-to-date off, linear-history requirement dropped.

Dependency reconciliation (max of develop/main)

Package / toolVersion
Microsoft.SourceLink.GitHub10.0.201
Serilog4.3.1
Microsoft.NET.Test.Sdk18.4.0
xunit.analyzers1.27.0
csharpier (tool)1.2.6
husky (tool)0.9.1

Everything else is exactly the develop tree (see #320 for the full change description). Net diff vs develop is only the six version bumps above.

Maintainer follow-ups (after merge)

  • Add CODEGEN_APP_CLIENT_ID / CODEGEN_APP_PRIVATE_KEY (GitHub App) to both Actions and Dependabot secret stores for the merge-bot.
  • Update the develop ruleset's required check to Check pull request workflow status (the main ruleset is already updated).
  • Bump develop's Directory.Packages.props / tools to match so the branches stay in sync (or let Dependabot do it).
  • Trigger the first publish via publish-release.yml → Run workflow once secrets are in place.

🤖 Generated with Claude Code

dependabotBotand others added 30 commits August 19, 2025 20:51
Bumps csharpier from 1.1.1 to 1.1.2
Bumps xunit.analyzers from 1.23.0 to 1.24.0
Bumps xunit.runner.visualstudio from 3.1.3 to 3.1.4
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.1.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
- dependency-name: xunit.analyzers
dependency-version: 1.24.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
- dependency-name: xunit.runner.visualstudio
dependency-version: 3.1.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-0259308462
Bump the nuget-deps group with 3 updates
Bumps xunit.runner.visualstudio from 3.1.4 to 3.1.5
---
updated-dependencies:
- dependency-name: xunit.runner.visualstudio
dependency-version: 3.1.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…evelop/nuget-deps-6aadeae1b1
Bump the nuget-deps group with 1 update
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-39349b7924
Bump csharpier from 1.1.2 to 1.2.1
---
updated-dependencies:
- dependency-name: Serilog.Sinks.Console
dependency-version: 6.1.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…nuget-deps-602f419b37
Bump Serilog.Sinks.Console from 6.0.0 to 6.1.1
Bumps csharpier from 1.2.1 to 1.2.3
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-1689e99d0a
Bump the nuget-deps group with 1 update
Bumps the actions-deps group with 2 updates in the / directory: [actions/setup-dotnet](https://github.com/actions/setup-dotnet) and [actions/checkout](https://github.com/actions/checkout).
Updates `actions/setup-dotnet` from 4 to 5
- [Release notes](https://github.com/actions/setup-dotnet/releases)
- [Commits](actions/setup-dotnet@v4...v5)
Updates `actions/checkout` from 5 to 6
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v5...v6)
---
updated-dependencies:
- dependency-name: actions/setup-dotnet
dependency-version: '5'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
- dependency-name: actions/checkout
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps csharpier from 1.2.3 to 1.2.4
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-133b2bc611
Bump the nuget-deps group with 1 update
Bumps csharpier from 1.2.4 to 1.2.5
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-262ca43251
Bump the nuget-deps group with 1 update
* Initial plan
* Add using statement and simplify CallerMemberName attributes
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
* Initial plan
* Make HttpClient timeout configurable via TimeoutSeconds property
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Initial plan
* Replace redundant ToString() with string interpolation in FileExAsyncTests
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
* Initial plan
* Replace explicit ToString() calls with string interpolation
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
…304)
Bumps the actions-deps group with 1 update: [dependabot/fetch-metadata](https://github.com/dependabot/fetch-metadata).
Updates `dependabot/fetch-metadata` from 2 to 3
- [Release notes](https://github.com/dependabot/fetch-metadata/releases)
- [Commits](dependabot/fetch-metadata@v2...v3)
---
updated-dependencies:
- dependency-name: dependabot/fetch-metadata
dependency-version: '3'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
ptr727 added 2 commits June 4, 2026 18:28
* Convert to two-phase dual-publish release model
Replace publish-on-push with the ProjectTemplate/LanguageTags two-phase
model: PRs smoke-test only, and publish-release.yml publishes both branches
on a weekly schedule (Mon 02:00 UTC) or manual dispatch, with idempotent
no-op republish. Adopt the reusable workflow set (get-version,
build-nugetlibrary, build-release, build-datebadge), a branch-aware
Dependabot merge-bot, Central Package Management, and an AGENTS.md tracking
the template. NuGet.org-only (drop GitHub Packages); no Docker/exe/PyPI/codegen.
Reconcile the template's strict analyzers (AnalysisMode All +
TreatWarningsAsErrors) with the brownfield library by relaxing specific
rules in .editorconfig and IL3058 via NoWarn, all documented.
* Normalize line endings to .editorconfig; fix husky hook
Convert the workflow YAML, dependabot.yml, and AGENTS.md (added LF) to CRLF
per .editorconfig, and make .husky/pre-commit LF + executable so its shebang
execs on Linux/WSL. Add an .editorconfig rule pinning the hook to LF.
* Quote "$GITHUB_OUTPUT" in date-badge task
Resolve the one-time old->new structural conflicts in develop's favour
(new reusable workflows, CPM, AGENTS.md, reformatting) and take the max
dependency/tool versions so main's newer Dependabot bumps are not regressed
(SourceLink 10.0.201, Serilog 4.3.1, Microsoft.NET.Test.Sdk 18.4.0,
xunit.analyzers 1.27.0, csharpier 1.2.6, husky 0.9.1).
CopilotAI review requested due to automatic review settings June 5, 2026 02:26

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Promotes the repository to the two-phase, dual-publish release model on main, aligning CI/CD, dependency management, and repo process documentation with the template-driven structure introduced on develop (with select version reconciliations to avoid regressing Dependabot bumps).

Changes:

  • Introduces the new CI/CD workflow set (PR smoke-test + scheduled/manual publish + Dependabot merge-bot) and removes the legacy publish + dependabot automerge workflows.
  • Switches to Central Package Management (Directory.Build.props + Directory.Packages.props) and updates project files accordingly (incl. IL3058 suppression for AOT projects).
  • Adds/updates repo process & configuration files (AGENTS.md, .editorconfig husky LF rule, .gitignore, README badge, solution items).

Reviewed changes

Copilot reviewed 38 out of 40 changed files in this pull request and generated 4 comments.

Show a summary per file
FileDescription
UtilitiesTests/UtilitiesTests.csprojMoves package versions to central management.
UtilitiesTests/UtilitiesTests.csRemoves now-redundant usings (implicit usings).
UtilitiesTests/StringHistoryTests.csRemoves now-redundant usings.
UtilitiesTests/StringCompressionTests.csRemoves now-redundant usings.
UtilitiesTests/StringCompressionAsyncTests.csRemoves now-redundant usings.
UtilitiesTests/FileExAsyncTests.csRemoves now-redundant usings.
UtilitiesTests/ExtensionsTests.csAdjusts null-handling tests; trims usings.
UtilitiesTests/DownloadTests.csRemoves now-redundant usings.
UtilitiesTests/DownloadAsyncTests.csRemoves now-redundant usings.
UtilitiesTests/ConsoleTests.csRemoves now-redundant usings.
Utilities/Utilities.csprojCentralizes TF/analyzers; suppresses IL3058; packable.
Utilities/StringHistory.csRemoves now-redundant usings.
Utilities/StringCompression.csRemoves now-redundant usings.
Utilities/Format.csRemoves now-redundant usings.
Utilities/FileExOptions.csRemoves now-redundant usings.
Utilities/FileEx.csRemoves now-redundant usings.
Utilities/Extensions.csRemoves now-redundant usings.
Utilities/Download.csRemoves now-redundant usings.
Utilities/ConsoleEx.csRemoves now-redundant usings.
Utilities/CommandLineEx.csRemoves now-redundant usings.
Utilities.slnxAdds new solution items + workflow files.
Sandbox/Sandbox.csprojCentralizes packages; suppresses IL3058.
Sandbox/Program.csMinor cleanup (AppContext usage).
README.mdUpdates workflow status badge to new workflow.
Directory.Packages.propsAdds centralized package versions.
Directory.Build.propsAdds shared build properties/analyzer strictness.
AGENTS.mdDocuments branching/release/workflow conventions.
.husky/pre-commitNormalizes hook file (LF/shebang handling).
.gitignoreIgnores .artifacts output directory.
.github/workflows/test-pull-request.ymlNew PR test/smoke build workflow + required-check aggregator.
.github/workflows/publish-release.ymlNew scheduled/manual publisher with two-phase gating.
.github/workflows/merge-bot-pull-request.ymlNew Dependabot merge-bot using app token + branch-aware merge method.
.github/workflows/get-version-task.ymlNew reusable NBGV version task.
.github/workflows/build-release-task.ymlNew orchestrator reusable workflow (build + optional publish).
.github/workflows/build-nugetlibrary-task.ymlNew reusable NuGet build/push task with artifacts.
.github/workflows/build-datebadge-task.ymlNew reusable BYOB date badge task.
.github/workflows/DependabotAutoMerge.ymlRemoves legacy Dependabot auto-merge workflow.
.github/workflows/BuildPublishPipeline.ymlRemoves legacy publish-on-push workflow.
.github/dependabot.ymlDuplicates ecosystems per-branch (main/develop).
.editorconfigAdds Husky hook LF rule + analyzer relaxations.

Comment threadUtilitiesTests/ExtensionsTests.cs
Comment threadUtilitiesTests/ExtensionsTests.cs
Comment threadUtilitiesTests/ExtensionsTests.cs
Comment thread.github/workflows/build-datebadge-task.yml
ptr727 added a commit that referenced this pull request Jun 5, 2026
## Summary
Land the two-phase dual-publish model on `main`, with **fully signed &
GitHub-verified history**. This is `main` merged with `develop`
(`0f1616d`), the one-time old→new structural conflicts resolved in
**develop's favour**, and the **max dependency/tool versions** taken so
`main`'s newer Dependabot bumps are not regressed.
All introduced commits are committer = `Pieter Viljoen
<ptr727@users.noreply.github.com>` and verified, satisfying
`required_signatures` (supersedes #322/#323, which carried unverifiable
web-flow-committed history).
### Dependency reconciliation (max of develop/main)
| Package / tool | Version |
| --- | --- |
| Microsoft.SourceLink.GitHub | 10.0.201 |
| Serilog | 4.3.1 |
| Microsoft.NET.Test.Sdk | 18.4.0 |
| xunit.analyzers | 1.27.0 |
| csharpier (tool) | 1.2.6 |
| husky (tool) | 0.9.1 |
Net diff vs `develop` is only the six version bumps above. See #320 for
the full change description.
## Maintainer follow-ups (after merge)
- Add `CODEGEN_APP_CLIENT_ID` / `CODEGEN_APP_PRIVATE_KEY` (GitHub App)
to **both** Actions and Dependabot secret stores for the merge-bot.
- Let Dependabot bring `develop`'s deps up to match (or open a small
sync PR).
- Kick off the first publish via **Actions → publish-release.yml → Run
workflow** once secrets are in.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
@ptr727ptr727 closed this Jun 5, 2026
@ptr727
ptr727 deleted the release/dualpublish branch June 5, 2026 13:13
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Release: two-phase dual-publish release model - #322

Closed
ptr727 wants to merge 32 commits into
mainfrom
release/dualpublish
Closed

Release: two-phase dual-publish release model#322
ptr727 wants to merge 32 commits into
mainfrom
release/dualpublish

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Summary

Release the two-phase dual-publish model to main. This branch is main merged with develop (the squash from #320), with the one-time old→new structural conflicts resolved in develop's favour and the max dependency/tool versions taken so main's newer Dependabot bumps are not regressed.

Supersedes #321 (the direct developmain PR, which had inherent merge conflicts from the old merge base). The main ruleset has been updated to the new model: required check is now Check pull request workflow status, merge-commit only, strict/up-to-date off, linear-history requirement dropped.

Dependency reconciliation (max of develop/main)

Package / toolVersion
Microsoft.SourceLink.GitHub10.0.201
Serilog4.3.1
Microsoft.NET.Test.Sdk18.4.0
xunit.analyzers1.27.0
csharpier (tool)1.2.6
husky (tool)0.9.1

Everything else is exactly the develop tree (see #320 for the full change description). Net diff vs develop is only the six version bumps above.

Maintainer follow-ups (after merge)

  • Add CODEGEN_APP_CLIENT_ID / CODEGEN_APP_PRIVATE_KEY (GitHub App) to both Actions and Dependabot secret stores for the merge-bot.
  • Update the develop ruleset's required check to Check pull request workflow status (the main ruleset is already updated).
  • Bump develop's Directory.Packages.props / tools to match so the branches stay in sync (or let Dependabot do it).
  • Trigger the first publish via publish-release.yml → Run workflow once secrets are in place.

🤖 Generated with Claude Code

dependabotBotand others added 30 commits August 19, 2025 20:51
Bumps csharpier from 1.1.1 to 1.1.2
Bumps xunit.analyzers from 1.23.0 to 1.24.0
Bumps xunit.runner.visualstudio from 3.1.3 to 3.1.4
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.1.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
- dependency-name: xunit.analyzers
dependency-version: 1.24.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
- dependency-name: xunit.runner.visualstudio
dependency-version: 3.1.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-0259308462
Bump the nuget-deps group with 3 updates
Bumps xunit.runner.visualstudio from 3.1.4 to 3.1.5
---
updated-dependencies:
- dependency-name: xunit.runner.visualstudio
dependency-version: 3.1.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…evelop/nuget-deps-6aadeae1b1
Bump the nuget-deps group with 1 update
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-39349b7924
Bump csharpier from 1.1.2 to 1.2.1
---
updated-dependencies:
- dependency-name: Serilog.Sinks.Console
dependency-version: 6.1.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…nuget-deps-602f419b37
Bump Serilog.Sinks.Console from 6.0.0 to 6.1.1
Bumps csharpier from 1.2.1 to 1.2.3
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-1689e99d0a
Bump the nuget-deps group with 1 update
Bumps the actions-deps group with 2 updates in the / directory: [actions/setup-dotnet](https://github.com/actions/setup-dotnet) and [actions/checkout](https://github.com/actions/checkout).
Updates `actions/setup-dotnet` from 4 to 5
- [Release notes](https://github.com/actions/setup-dotnet/releases)
- [Commits](actions/setup-dotnet@v4...v5)
Updates `actions/checkout` from 5 to 6
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v5...v6)
---
updated-dependencies:
- dependency-name: actions/setup-dotnet
dependency-version: '5'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
- dependency-name: actions/checkout
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps csharpier from 1.2.3 to 1.2.4
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-133b2bc611
Bump the nuget-deps group with 1 update
Bumps csharpier from 1.2.4 to 1.2.5
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-262ca43251
Bump the nuget-deps group with 1 update
* Initial plan
* Add using statement and simplify CallerMemberName attributes
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
* Initial plan
* Make HttpClient timeout configurable via TimeoutSeconds property
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Initial plan
* Replace redundant ToString() with string interpolation in FileExAsyncTests
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
* Initial plan
* Replace explicit ToString() calls with string interpolation
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
…304)
Bumps the actions-deps group with 1 update: [dependabot/fetch-metadata](https://github.com/dependabot/fetch-metadata).
Updates `dependabot/fetch-metadata` from 2 to 3
- [Release notes](https://github.com/dependabot/fetch-metadata/releases)
- [Commits](dependabot/fetch-metadata@v2...v3)
---
updated-dependencies:
- dependency-name: dependabot/fetch-metadata
dependency-version: '3'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
ptr727 added 2 commits June 4, 2026 18:28
* Convert to two-phase dual-publish release model
Replace publish-on-push with the ProjectTemplate/LanguageTags two-phase
model: PRs smoke-test only, and publish-release.yml publishes both branches
on a weekly schedule (Mon 02:00 UTC) or manual dispatch, with idempotent
no-op republish. Adopt the reusable workflow set (get-version,
build-nugetlibrary, build-release, build-datebadge), a branch-aware
Dependabot merge-bot, Central Package Management, and an AGENTS.md tracking
the template. NuGet.org-only (drop GitHub Packages); no Docker/exe/PyPI/codegen.
Reconcile the template's strict analyzers (AnalysisMode All +
TreatWarningsAsErrors) with the brownfield library by relaxing specific
rules in .editorconfig and IL3058 via NoWarn, all documented.
* Normalize line endings to .editorconfig; fix husky hook
Convert the workflow YAML, dependabot.yml, and AGENTS.md (added LF) to CRLF
per .editorconfig, and make .husky/pre-commit LF + executable so its shebang
execs on Linux/WSL. Add an .editorconfig rule pinning the hook to LF.
* Quote "$GITHUB_OUTPUT" in date-badge task
Resolve the one-time old->new structural conflicts in develop's favour
(new reusable workflows, CPM, AGENTS.md, reformatting) and take the max
dependency/tool versions so main's newer Dependabot bumps are not regressed
(SourceLink 10.0.201, Serilog 4.3.1, Microsoft.NET.Test.Sdk 18.4.0,
xunit.analyzers 1.27.0, csharpier 1.2.6, husky 0.9.1).
CopilotAI review requested due to automatic review settings June 5, 2026 02:26

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Promotes the repository to the two-phase, dual-publish release model on main, aligning CI/CD, dependency management, and repo process documentation with the template-driven structure introduced on develop (with select version reconciliations to avoid regressing Dependabot bumps).

Changes:

  • Introduces the new CI/CD workflow set (PR smoke-test + scheduled/manual publish + Dependabot merge-bot) and removes the legacy publish + dependabot automerge workflows.
  • Switches to Central Package Management (Directory.Build.props + Directory.Packages.props) and updates project files accordingly (incl. IL3058 suppression for AOT projects).
  • Adds/updates repo process & configuration files (AGENTS.md, .editorconfig husky LF rule, .gitignore, README badge, solution items).

Reviewed changes

Copilot reviewed 38 out of 40 changed files in this pull request and generated 4 comments.

Show a summary per file
FileDescription
UtilitiesTests/UtilitiesTests.csprojMoves package versions to central management.
UtilitiesTests/UtilitiesTests.csRemoves now-redundant usings (implicit usings).
UtilitiesTests/StringHistoryTests.csRemoves now-redundant usings.
UtilitiesTests/StringCompressionTests.csRemoves now-redundant usings.
UtilitiesTests/StringCompressionAsyncTests.csRemoves now-redundant usings.
UtilitiesTests/FileExAsyncTests.csRemoves now-redundant usings.
UtilitiesTests/ExtensionsTests.csAdjusts null-handling tests; trims usings.
UtilitiesTests/DownloadTests.csRemoves now-redundant usings.
UtilitiesTests/DownloadAsyncTests.csRemoves now-redundant usings.
UtilitiesTests/ConsoleTests.csRemoves now-redundant usings.
Utilities/Utilities.csprojCentralizes TF/analyzers; suppresses IL3058; packable.
Utilities/StringHistory.csRemoves now-redundant usings.
Utilities/StringCompression.csRemoves now-redundant usings.
Utilities/Format.csRemoves now-redundant usings.
Utilities/FileExOptions.csRemoves now-redundant usings.
Utilities/FileEx.csRemoves now-redundant usings.
Utilities/Extensions.csRemoves now-redundant usings.
Utilities/Download.csRemoves now-redundant usings.
Utilities/ConsoleEx.csRemoves now-redundant usings.
Utilities/CommandLineEx.csRemoves now-redundant usings.
Utilities.slnxAdds new solution items + workflow files.
Sandbox/Sandbox.csprojCentralizes packages; suppresses IL3058.
Sandbox/Program.csMinor cleanup (AppContext usage).
README.mdUpdates workflow status badge to new workflow.
Directory.Packages.propsAdds centralized package versions.
Directory.Build.propsAdds shared build properties/analyzer strictness.
AGENTS.mdDocuments branching/release/workflow conventions.
.husky/pre-commitNormalizes hook file (LF/shebang handling).
.gitignoreIgnores .artifacts output directory.
.github/workflows/test-pull-request.ymlNew PR test/smoke build workflow + required-check aggregator.
.github/workflows/publish-release.ymlNew scheduled/manual publisher with two-phase gating.
.github/workflows/merge-bot-pull-request.ymlNew Dependabot merge-bot using app token + branch-aware merge method.
.github/workflows/get-version-task.ymlNew reusable NBGV version task.
.github/workflows/build-release-task.ymlNew orchestrator reusable workflow (build + optional publish).
.github/workflows/build-nugetlibrary-task.ymlNew reusable NuGet build/push task with artifacts.
.github/workflows/build-datebadge-task.ymlNew reusable BYOB date badge task.
.github/workflows/DependabotAutoMerge.ymlRemoves legacy Dependabot auto-merge workflow.
.github/workflows/BuildPublishPipeline.ymlRemoves legacy publish-on-push workflow.
.github/dependabot.ymlDuplicates ecosystems per-branch (main/develop).
.editorconfigAdds Husky hook LF rule + analyzer relaxations.

Comment threadUtilitiesTests/ExtensionsTests.cs
Comment threadUtilitiesTests/ExtensionsTests.cs
Comment threadUtilitiesTests/ExtensionsTests.cs
Comment thread.github/workflows/build-datebadge-task.yml
ptr727 added a commit that referenced this pull request Jun 5, 2026
## Summary
Land the two-phase dual-publish model on `main`, with **fully signed &
GitHub-verified history**. This is `main` merged with `develop`
(`0f1616d`), the one-time old→new structural conflicts resolved in
**develop's favour**, and the **max dependency/tool versions** taken so
`main`'s newer Dependabot bumps are not regressed.
All introduced commits are committer = `Pieter Viljoen
<ptr727@users.noreply.github.com>` and verified, satisfying
`required_signatures` (supersedes #322/#323, which carried unverifiable
web-flow-committed history).
### Dependency reconciliation (max of develop/main)
| Package / tool | Version |
| --- | --- |
| Microsoft.SourceLink.GitHub | 10.0.201 |
| Serilog | 4.3.1 |
| Microsoft.NET.Test.Sdk | 18.4.0 |
| xunit.analyzers | 1.27.0 |
| csharpier (tool) | 1.2.6 |
| husky (tool) | 0.9.1 |
Net diff vs `develop` is only the six version bumps above. See #320 for
the full change description.
## Maintainer follow-ups (after merge)
- Add `CODEGEN_APP_CLIENT_ID` / `CODEGEN_APP_PRIVATE_KEY` (GitHub App)
to **both** Actions and Dependabot secret stores for the merge-bot.
- Let Dependabot bring `develop`'s deps up to match (or open a small
sync PR).
- Kick off the first publish via **Actions → publish-release.yml → Run
workflow** once secrets are in.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
@ptr727ptr727 closed this Jun 5, 2026
@ptr727
ptr727 deleted the release/dualpublish branch June 5, 2026 13:13
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Release: two-phase dual-publish release model - #322

Closed
ptr727 wants to merge 32 commits into
mainfrom
release/dualpublish
Closed

Release: two-phase dual-publish release model#322
ptr727 wants to merge 32 commits into
mainfrom
release/dualpublish

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Summary

Release the two-phase dual-publish model to main. This branch is main merged with develop (the squash from #320), with the one-time old→new structural conflicts resolved in develop's favour and the max dependency/tool versions taken so main's newer Dependabot bumps are not regressed.

Supersedes #321 (the direct developmain PR, which had inherent merge conflicts from the old merge base). The main ruleset has been updated to the new model: required check is now Check pull request workflow status, merge-commit only, strict/up-to-date off, linear-history requirement dropped.

Dependency reconciliation (max of develop/main)

Package / toolVersion
Microsoft.SourceLink.GitHub10.0.201
Serilog4.3.1
Microsoft.NET.Test.Sdk18.4.0
xunit.analyzers1.27.0
csharpier (tool)1.2.6
husky (tool)0.9.1

Everything else is exactly the develop tree (see #320 for the full change description). Net diff vs develop is only the six version bumps above.

Maintainer follow-ups (after merge)

  • Add CODEGEN_APP_CLIENT_ID / CODEGEN_APP_PRIVATE_KEY (GitHub App) to both Actions and Dependabot secret stores for the merge-bot.
  • Update the develop ruleset's required check to Check pull request workflow status (the main ruleset is already updated).
  • Bump develop's Directory.Packages.props / tools to match so the branches stay in sync (or let Dependabot do it).
  • Trigger the first publish via publish-release.yml → Run workflow once secrets are in place.

🤖 Generated with Claude Code

dependabotBotand others added 30 commits August 19, 2025 20:51
Bumps csharpier from 1.1.1 to 1.1.2
Bumps xunit.analyzers from 1.23.0 to 1.24.0
Bumps xunit.runner.visualstudio from 3.1.3 to 3.1.4
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.1.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
- dependency-name: xunit.analyzers
dependency-version: 1.24.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
- dependency-name: xunit.runner.visualstudio
dependency-version: 3.1.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-0259308462
Bump the nuget-deps group with 3 updates
Bumps xunit.runner.visualstudio from 3.1.4 to 3.1.5
---
updated-dependencies:
- dependency-name: xunit.runner.visualstudio
dependency-version: 3.1.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…evelop/nuget-deps-6aadeae1b1
Bump the nuget-deps group with 1 update
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-39349b7924
Bump csharpier from 1.1.2 to 1.2.1
---
updated-dependencies:
- dependency-name: Serilog.Sinks.Console
dependency-version: 6.1.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…nuget-deps-602f419b37
Bump Serilog.Sinks.Console from 6.0.0 to 6.1.1
Bumps csharpier from 1.2.1 to 1.2.3
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-1689e99d0a
Bump the nuget-deps group with 1 update
Bumps the actions-deps group with 2 updates in the / directory: [actions/setup-dotnet](https://github.com/actions/setup-dotnet) and [actions/checkout](https://github.com/actions/checkout).
Updates `actions/setup-dotnet` from 4 to 5
- [Release notes](https://github.com/actions/setup-dotnet/releases)
- [Commits](actions/setup-dotnet@v4...v5)
Updates `actions/checkout` from 5 to 6
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v5...v6)
---
updated-dependencies:
- dependency-name: actions/setup-dotnet
dependency-version: '5'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
- dependency-name: actions/checkout
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps csharpier from 1.2.3 to 1.2.4
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-133b2bc611
Bump the nuget-deps group with 1 update
Bumps csharpier from 1.2.4 to 1.2.5
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-262ca43251
Bump the nuget-deps group with 1 update
* Initial plan
* Add using statement and simplify CallerMemberName attributes
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
* Initial plan
* Make HttpClient timeout configurable via TimeoutSeconds property
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Initial plan
* Replace redundant ToString() with string interpolation in FileExAsyncTests
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
* Initial plan
* Replace explicit ToString() calls with string interpolation
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
…304)
Bumps the actions-deps group with 1 update: [dependabot/fetch-metadata](https://github.com/dependabot/fetch-metadata).
Updates `dependabot/fetch-metadata` from 2 to 3
- [Release notes](https://github.com/dependabot/fetch-metadata/releases)
- [Commits](dependabot/fetch-metadata@v2...v3)
---
updated-dependencies:
- dependency-name: dependabot/fetch-metadata
dependency-version: '3'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
ptr727 added 2 commits June 4, 2026 18:28
* Convert to two-phase dual-publish release model
Replace publish-on-push with the ProjectTemplate/LanguageTags two-phase
model: PRs smoke-test only, and publish-release.yml publishes both branches
on a weekly schedule (Mon 02:00 UTC) or manual dispatch, with idempotent
no-op republish. Adopt the reusable workflow set (get-version,
build-nugetlibrary, build-release, build-datebadge), a branch-aware
Dependabot merge-bot, Central Package Management, and an AGENTS.md tracking
the template. NuGet.org-only (drop GitHub Packages); no Docker/exe/PyPI/codegen.
Reconcile the template's strict analyzers (AnalysisMode All +
TreatWarningsAsErrors) with the brownfield library by relaxing specific
rules in .editorconfig and IL3058 via NoWarn, all documented.
* Normalize line endings to .editorconfig; fix husky hook
Convert the workflow YAML, dependabot.yml, and AGENTS.md (added LF) to CRLF
per .editorconfig, and make .husky/pre-commit LF + executable so its shebang
execs on Linux/WSL. Add an .editorconfig rule pinning the hook to LF.
* Quote "$GITHUB_OUTPUT" in date-badge task
Resolve the one-time old->new structural conflicts in develop's favour
(new reusable workflows, CPM, AGENTS.md, reformatting) and take the max
dependency/tool versions so main's newer Dependabot bumps are not regressed
(SourceLink 10.0.201, Serilog 4.3.1, Microsoft.NET.Test.Sdk 18.4.0,
xunit.analyzers 1.27.0, csharpier 1.2.6, husky 0.9.1).
CopilotAI review requested due to automatic review settings June 5, 2026 02:26

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Promotes the repository to the two-phase, dual-publish release model on main, aligning CI/CD, dependency management, and repo process documentation with the template-driven structure introduced on develop (with select version reconciliations to avoid regressing Dependabot bumps).

Changes:

  • Introduces the new CI/CD workflow set (PR smoke-test + scheduled/manual publish + Dependabot merge-bot) and removes the legacy publish + dependabot automerge workflows.
  • Switches to Central Package Management (Directory.Build.props + Directory.Packages.props) and updates project files accordingly (incl. IL3058 suppression for AOT projects).
  • Adds/updates repo process & configuration files (AGENTS.md, .editorconfig husky LF rule, .gitignore, README badge, solution items).

Reviewed changes

Copilot reviewed 38 out of 40 changed files in this pull request and generated 4 comments.

Show a summary per file
FileDescription
UtilitiesTests/UtilitiesTests.csprojMoves package versions to central management.
UtilitiesTests/UtilitiesTests.csRemoves now-redundant usings (implicit usings).
UtilitiesTests/StringHistoryTests.csRemoves now-redundant usings.
UtilitiesTests/StringCompressionTests.csRemoves now-redundant usings.
UtilitiesTests/StringCompressionAsyncTests.csRemoves now-redundant usings.
UtilitiesTests/FileExAsyncTests.csRemoves now-redundant usings.
UtilitiesTests/ExtensionsTests.csAdjusts null-handling tests; trims usings.
UtilitiesTests/DownloadTests.csRemoves now-redundant usings.
UtilitiesTests/DownloadAsyncTests.csRemoves now-redundant usings.
UtilitiesTests/ConsoleTests.csRemoves now-redundant usings.
Utilities/Utilities.csprojCentralizes TF/analyzers; suppresses IL3058; packable.
Utilities/StringHistory.csRemoves now-redundant usings.
Utilities/StringCompression.csRemoves now-redundant usings.
Utilities/Format.csRemoves now-redundant usings.
Utilities/FileExOptions.csRemoves now-redundant usings.
Utilities/FileEx.csRemoves now-redundant usings.
Utilities/Extensions.csRemoves now-redundant usings.
Utilities/Download.csRemoves now-redundant usings.
Utilities/ConsoleEx.csRemoves now-redundant usings.
Utilities/CommandLineEx.csRemoves now-redundant usings.
Utilities.slnxAdds new solution items + workflow files.
Sandbox/Sandbox.csprojCentralizes packages; suppresses IL3058.
Sandbox/Program.csMinor cleanup (AppContext usage).
README.mdUpdates workflow status badge to new workflow.
Directory.Packages.propsAdds centralized package versions.
Directory.Build.propsAdds shared build properties/analyzer strictness.
AGENTS.mdDocuments branching/release/workflow conventions.
.husky/pre-commitNormalizes hook file (LF/shebang handling).
.gitignoreIgnores .artifacts output directory.
.github/workflows/test-pull-request.ymlNew PR test/smoke build workflow + required-check aggregator.
.github/workflows/publish-release.ymlNew scheduled/manual publisher with two-phase gating.
.github/workflows/merge-bot-pull-request.ymlNew Dependabot merge-bot using app token + branch-aware merge method.
.github/workflows/get-version-task.ymlNew reusable NBGV version task.
.github/workflows/build-release-task.ymlNew orchestrator reusable workflow (build + optional publish).
.github/workflows/build-nugetlibrary-task.ymlNew reusable NuGet build/push task with artifacts.
.github/workflows/build-datebadge-task.ymlNew reusable BYOB date badge task.
.github/workflows/DependabotAutoMerge.ymlRemoves legacy Dependabot auto-merge workflow.
.github/workflows/BuildPublishPipeline.ymlRemoves legacy publish-on-push workflow.
.github/dependabot.ymlDuplicates ecosystems per-branch (main/develop).
.editorconfigAdds Husky hook LF rule + analyzer relaxations.

Comment threadUtilitiesTests/ExtensionsTests.cs
Comment threadUtilitiesTests/ExtensionsTests.cs
Comment threadUtilitiesTests/ExtensionsTests.cs
Comment thread.github/workflows/build-datebadge-task.yml
ptr727 added a commit that referenced this pull request Jun 5, 2026
## Summary
Land the two-phase dual-publish model on `main`, with **fully signed &
GitHub-verified history**. This is `main` merged with `develop`
(`0f1616d`), the one-time old→new structural conflicts resolved in
**develop's favour**, and the **max dependency/tool versions** taken so
`main`'s newer Dependabot bumps are not regressed.
All introduced commits are committer = `Pieter Viljoen
<ptr727@users.noreply.github.com>` and verified, satisfying
`required_signatures` (supersedes #322/#323, which carried unverifiable
web-flow-committed history).
### Dependency reconciliation (max of develop/main)
| Package / tool | Version |
| --- | --- |
| Microsoft.SourceLink.GitHub | 10.0.201 |
| Serilog | 4.3.1 |
| Microsoft.NET.Test.Sdk | 18.4.0 |
| xunit.analyzers | 1.27.0 |
| csharpier (tool) | 1.2.6 |
| husky (tool) | 0.9.1 |
Net diff vs `develop` is only the six version bumps above. See #320 for
the full change description.
## Maintainer follow-ups (after merge)
- Add `CODEGEN_APP_CLIENT_ID` / `CODEGEN_APP_PRIVATE_KEY` (GitHub App)
to **both** Actions and Dependabot secret stores for the merge-bot.
- Let Dependabot bring `develop`'s deps up to match (or open a small
sync PR).
- Kick off the first publish via **Actions → publish-release.yml → Run
workflow** once secrets are in.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
@ptr727ptr727 closed this Jun 5, 2026
@ptr727
ptr727 deleted the release/dualpublish branch June 5, 2026 13:13
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Release: two-phase dual-publish release model - #322

Closed
ptr727 wants to merge 32 commits into
mainfrom
release/dualpublish
Closed

Release: two-phase dual-publish release model#322
ptr727 wants to merge 32 commits into
mainfrom
release/dualpublish

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Summary

Release the two-phase dual-publish model to main. This branch is main merged with develop (the squash from #320), with the one-time old→new structural conflicts resolved in develop's favour and the max dependency/tool versions taken so main's newer Dependabot bumps are not regressed.

Supersedes #321 (the direct developmain PR, which had inherent merge conflicts from the old merge base). The main ruleset has been updated to the new model: required check is now Check pull request workflow status, merge-commit only, strict/up-to-date off, linear-history requirement dropped.

Dependency reconciliation (max of develop/main)

Package / toolVersion
Microsoft.SourceLink.GitHub10.0.201
Serilog4.3.1
Microsoft.NET.Test.Sdk18.4.0
xunit.analyzers1.27.0
csharpier (tool)1.2.6
husky (tool)0.9.1

Everything else is exactly the develop tree (see #320 for the full change description). Net diff vs develop is only the six version bumps above.

Maintainer follow-ups (after merge)

  • Add CODEGEN_APP_CLIENT_ID / CODEGEN_APP_PRIVATE_KEY (GitHub App) to both Actions and Dependabot secret stores for the merge-bot.
  • Update the develop ruleset's required check to Check pull request workflow status (the main ruleset is already updated).
  • Bump develop's Directory.Packages.props / tools to match so the branches stay in sync (or let Dependabot do it).
  • Trigger the first publish via publish-release.yml → Run workflow once secrets are in place.

🤖 Generated with Claude Code

dependabotBotand others added 30 commits August 19, 2025 20:51
Bumps csharpier from 1.1.1 to 1.1.2
Bumps xunit.analyzers from 1.23.0 to 1.24.0
Bumps xunit.runner.visualstudio from 3.1.3 to 3.1.4
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.1.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
- dependency-name: xunit.analyzers
dependency-version: 1.24.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
- dependency-name: xunit.runner.visualstudio
dependency-version: 3.1.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-0259308462
Bump the nuget-deps group with 3 updates
Bumps xunit.runner.visualstudio from 3.1.4 to 3.1.5
---
updated-dependencies:
- dependency-name: xunit.runner.visualstudio
dependency-version: 3.1.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…evelop/nuget-deps-6aadeae1b1
Bump the nuget-deps group with 1 update
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-39349b7924
Bump csharpier from 1.1.2 to 1.2.1
---
updated-dependencies:
- dependency-name: Serilog.Sinks.Console
dependency-version: 6.1.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…nuget-deps-602f419b37
Bump Serilog.Sinks.Console from 6.0.0 to 6.1.1
Bumps csharpier from 1.2.1 to 1.2.3
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-1689e99d0a
Bump the nuget-deps group with 1 update
Bumps the actions-deps group with 2 updates in the / directory: [actions/setup-dotnet](https://github.com/actions/setup-dotnet) and [actions/checkout](https://github.com/actions/checkout).
Updates `actions/setup-dotnet` from 4 to 5
- [Release notes](https://github.com/actions/setup-dotnet/releases)
- [Commits](actions/setup-dotnet@v4...v5)
Updates `actions/checkout` from 5 to 6
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v5...v6)
---
updated-dependencies:
- dependency-name: actions/setup-dotnet
dependency-version: '5'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
- dependency-name: actions/checkout
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps csharpier from 1.2.3 to 1.2.4
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-133b2bc611
Bump the nuget-deps group with 1 update
Bumps csharpier from 1.2.4 to 1.2.5
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-262ca43251
Bump the nuget-deps group with 1 update
* Initial plan
* Add using statement and simplify CallerMemberName attributes
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
* Initial plan
* Make HttpClient timeout configurable via TimeoutSeconds property
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Initial plan
* Replace redundant ToString() with string interpolation in FileExAsyncTests
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
* Initial plan
* Replace explicit ToString() calls with string interpolation
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
…304)
Bumps the actions-deps group with 1 update: [dependabot/fetch-metadata](https://github.com/dependabot/fetch-metadata).
Updates `dependabot/fetch-metadata` from 2 to 3
- [Release notes](https://github.com/dependabot/fetch-metadata/releases)
- [Commits](dependabot/fetch-metadata@v2...v3)
---
updated-dependencies:
- dependency-name: dependabot/fetch-metadata
dependency-version: '3'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
ptr727 added 2 commits June 4, 2026 18:28
* Convert to two-phase dual-publish release model
Replace publish-on-push with the ProjectTemplate/LanguageTags two-phase
model: PRs smoke-test only, and publish-release.yml publishes both branches
on a weekly schedule (Mon 02:00 UTC) or manual dispatch, with idempotent
no-op republish. Adopt the reusable workflow set (get-version,
build-nugetlibrary, build-release, build-datebadge), a branch-aware
Dependabot merge-bot, Central Package Management, and an AGENTS.md tracking
the template. NuGet.org-only (drop GitHub Packages); no Docker/exe/PyPI/codegen.
Reconcile the template's strict analyzers (AnalysisMode All +
TreatWarningsAsErrors) with the brownfield library by relaxing specific
rules in .editorconfig and IL3058 via NoWarn, all documented.
* Normalize line endings to .editorconfig; fix husky hook
Convert the workflow YAML, dependabot.yml, and AGENTS.md (added LF) to CRLF
per .editorconfig, and make .husky/pre-commit LF + executable so its shebang
execs on Linux/WSL. Add an .editorconfig rule pinning the hook to LF.
* Quote "$GITHUB_OUTPUT" in date-badge task
Resolve the one-time old->new structural conflicts in develop's favour
(new reusable workflows, CPM, AGENTS.md, reformatting) and take the max
dependency/tool versions so main's newer Dependabot bumps are not regressed
(SourceLink 10.0.201, Serilog 4.3.1, Microsoft.NET.Test.Sdk 18.4.0,
xunit.analyzers 1.27.0, csharpier 1.2.6, husky 0.9.1).
CopilotAI review requested due to automatic review settings June 5, 2026 02:26

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Promotes the repository to the two-phase, dual-publish release model on main, aligning CI/CD, dependency management, and repo process documentation with the template-driven structure introduced on develop (with select version reconciliations to avoid regressing Dependabot bumps).

Changes:

  • Introduces the new CI/CD workflow set (PR smoke-test + scheduled/manual publish + Dependabot merge-bot) and removes the legacy publish + dependabot automerge workflows.
  • Switches to Central Package Management (Directory.Build.props + Directory.Packages.props) and updates project files accordingly (incl. IL3058 suppression for AOT projects).
  • Adds/updates repo process & configuration files (AGENTS.md, .editorconfig husky LF rule, .gitignore, README badge, solution items).

Reviewed changes

Copilot reviewed 38 out of 40 changed files in this pull request and generated 4 comments.

Show a summary per file
FileDescription
UtilitiesTests/UtilitiesTests.csprojMoves package versions to central management.
UtilitiesTests/UtilitiesTests.csRemoves now-redundant usings (implicit usings).
UtilitiesTests/StringHistoryTests.csRemoves now-redundant usings.
UtilitiesTests/StringCompressionTests.csRemoves now-redundant usings.
UtilitiesTests/StringCompressionAsyncTests.csRemoves now-redundant usings.
UtilitiesTests/FileExAsyncTests.csRemoves now-redundant usings.
UtilitiesTests/ExtensionsTests.csAdjusts null-handling tests; trims usings.
UtilitiesTests/DownloadTests.csRemoves now-redundant usings.
UtilitiesTests/DownloadAsyncTests.csRemoves now-redundant usings.
UtilitiesTests/ConsoleTests.csRemoves now-redundant usings.
Utilities/Utilities.csprojCentralizes TF/analyzers; suppresses IL3058; packable.
Utilities/StringHistory.csRemoves now-redundant usings.
Utilities/StringCompression.csRemoves now-redundant usings.
Utilities/Format.csRemoves now-redundant usings.
Utilities/FileExOptions.csRemoves now-redundant usings.
Utilities/FileEx.csRemoves now-redundant usings.
Utilities/Extensions.csRemoves now-redundant usings.
Utilities/Download.csRemoves now-redundant usings.
Utilities/ConsoleEx.csRemoves now-redundant usings.
Utilities/CommandLineEx.csRemoves now-redundant usings.
Utilities.slnxAdds new solution items + workflow files.
Sandbox/Sandbox.csprojCentralizes packages; suppresses IL3058.
Sandbox/Program.csMinor cleanup (AppContext usage).
README.mdUpdates workflow status badge to new workflow.
Directory.Packages.propsAdds centralized package versions.
Directory.Build.propsAdds shared build properties/analyzer strictness.
AGENTS.mdDocuments branching/release/workflow conventions.
.husky/pre-commitNormalizes hook file (LF/shebang handling).
.gitignoreIgnores .artifacts output directory.
.github/workflows/test-pull-request.ymlNew PR test/smoke build workflow + required-check aggregator.
.github/workflows/publish-release.ymlNew scheduled/manual publisher with two-phase gating.
.github/workflows/merge-bot-pull-request.ymlNew Dependabot merge-bot using app token + branch-aware merge method.
.github/workflows/get-version-task.ymlNew reusable NBGV version task.
.github/workflows/build-release-task.ymlNew orchestrator reusable workflow (build + optional publish).
.github/workflows/build-nugetlibrary-task.ymlNew reusable NuGet build/push task with artifacts.
.github/workflows/build-datebadge-task.ymlNew reusable BYOB date badge task.
.github/workflows/DependabotAutoMerge.ymlRemoves legacy Dependabot auto-merge workflow.
.github/workflows/BuildPublishPipeline.ymlRemoves legacy publish-on-push workflow.
.github/dependabot.ymlDuplicates ecosystems per-branch (main/develop).
.editorconfigAdds Husky hook LF rule + analyzer relaxations.

Comment threadUtilitiesTests/ExtensionsTests.cs
Comment threadUtilitiesTests/ExtensionsTests.cs
Comment threadUtilitiesTests/ExtensionsTests.cs
Comment thread.github/workflows/build-datebadge-task.yml
ptr727 added a commit that referenced this pull request Jun 5, 2026
## Summary
Land the two-phase dual-publish model on `main`, with **fully signed &
GitHub-verified history**. This is `main` merged with `develop`
(`0f1616d`), the one-time old→new structural conflicts resolved in
**develop's favour**, and the **max dependency/tool versions** taken so
`main`'s newer Dependabot bumps are not regressed.
All introduced commits are committer = `Pieter Viljoen
<ptr727@users.noreply.github.com>` and verified, satisfying
`required_signatures` (supersedes #322/#323, which carried unverifiable
web-flow-committed history).
### Dependency reconciliation (max of develop/main)
| Package / tool | Version |
| --- | --- |
| Microsoft.SourceLink.GitHub | 10.0.201 |
| Serilog | 4.3.1 |
| Microsoft.NET.Test.Sdk | 18.4.0 |
| xunit.analyzers | 1.27.0 |
| csharpier (tool) | 1.2.6 |
| husky (tool) | 0.9.1 |
Net diff vs `develop` is only the six version bumps above. See #320 for
the full change description.
## Maintainer follow-ups (after merge)
- Add `CODEGEN_APP_CLIENT_ID` / `CODEGEN_APP_PRIVATE_KEY` (GitHub App)
to **both** Actions and Dependabot secret stores for the merge-bot.
- Let Dependabot bring `develop`'s deps up to match (or open a small
sync PR).
- Kick off the first publish via **Actions → publish-release.yml → Run
workflow** once secrets are in.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
@ptr727ptr727 closed this Jun 5, 2026
@ptr727
ptr727 deleted the release/dualpublish branch June 5, 2026 13:13
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Release: two-phase dual-publish release model - #322

Closed
ptr727 wants to merge 32 commits into
mainfrom
release/dualpublish
Closed

Release: two-phase dual-publish release model#322
ptr727 wants to merge 32 commits into
mainfrom
release/dualpublish

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Summary

Release the two-phase dual-publish model to main. This branch is main merged with develop (the squash from #320), with the one-time old→new structural conflicts resolved in develop's favour and the max dependency/tool versions taken so main's newer Dependabot bumps are not regressed.

Supersedes #321 (the direct developmain PR, which had inherent merge conflicts from the old merge base). The main ruleset has been updated to the new model: required check is now Check pull request workflow status, merge-commit only, strict/up-to-date off, linear-history requirement dropped.

Dependency reconciliation (max of develop/main)

Package / toolVersion
Microsoft.SourceLink.GitHub10.0.201
Serilog4.3.1
Microsoft.NET.Test.Sdk18.4.0
xunit.analyzers1.27.0
csharpier (tool)1.2.6
husky (tool)0.9.1

Everything else is exactly the develop tree (see #320 for the full change description). Net diff vs develop is only the six version bumps above.

Maintainer follow-ups (after merge)

  • Add CODEGEN_APP_CLIENT_ID / CODEGEN_APP_PRIVATE_KEY (GitHub App) to both Actions and Dependabot secret stores for the merge-bot.
  • Update the develop ruleset's required check to Check pull request workflow status (the main ruleset is already updated).
  • Bump develop's Directory.Packages.props / tools to match so the branches stay in sync (or let Dependabot do it).
  • Trigger the first publish via publish-release.yml → Run workflow once secrets are in place.

🤖 Generated with Claude Code

dependabotBotand others added 30 commits August 19, 2025 20:51
Bumps csharpier from 1.1.1 to 1.1.2
Bumps xunit.analyzers from 1.23.0 to 1.24.0
Bumps xunit.runner.visualstudio from 3.1.3 to 3.1.4
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.1.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
- dependency-name: xunit.analyzers
dependency-version: 1.24.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
- dependency-name: xunit.runner.visualstudio
dependency-version: 3.1.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-0259308462
Bump the nuget-deps group with 3 updates
Bumps xunit.runner.visualstudio from 3.1.4 to 3.1.5
---
updated-dependencies:
- dependency-name: xunit.runner.visualstudio
dependency-version: 3.1.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…evelop/nuget-deps-6aadeae1b1
Bump the nuget-deps group with 1 update
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-39349b7924
Bump csharpier from 1.1.2 to 1.2.1
---
updated-dependencies:
- dependency-name: Serilog.Sinks.Console
dependency-version: 6.1.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…nuget-deps-602f419b37
Bump Serilog.Sinks.Console from 6.0.0 to 6.1.1
Bumps csharpier from 1.2.1 to 1.2.3
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-1689e99d0a
Bump the nuget-deps group with 1 update
Bumps the actions-deps group with 2 updates in the / directory: [actions/setup-dotnet](https://github.com/actions/setup-dotnet) and [actions/checkout](https://github.com/actions/checkout).
Updates `actions/setup-dotnet` from 4 to 5
- [Release notes](https://github.com/actions/setup-dotnet/releases)
- [Commits](actions/setup-dotnet@v4...v5)
Updates `actions/checkout` from 5 to 6
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v5...v6)
---
updated-dependencies:
- dependency-name: actions/setup-dotnet
dependency-version: '5'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
- dependency-name: actions/checkout
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps csharpier from 1.2.3 to 1.2.4
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-133b2bc611
Bump the nuget-deps group with 1 update
Bumps csharpier from 1.2.4 to 1.2.5
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-262ca43251
Bump the nuget-deps group with 1 update
* Initial plan
* Add using statement and simplify CallerMemberName attributes
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
* Initial plan
* Make HttpClient timeout configurable via TimeoutSeconds property
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Initial plan
* Replace redundant ToString() with string interpolation in FileExAsyncTests
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
* Initial plan
* Replace explicit ToString() calls with string interpolation
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
…304)
Bumps the actions-deps group with 1 update: [dependabot/fetch-metadata](https://github.com/dependabot/fetch-metadata).
Updates `dependabot/fetch-metadata` from 2 to 3
- [Release notes](https://github.com/dependabot/fetch-metadata/releases)
- [Commits](dependabot/fetch-metadata@v2...v3)
---
updated-dependencies:
- dependency-name: dependabot/fetch-metadata
dependency-version: '3'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
ptr727 added 2 commits June 4, 2026 18:28
* Convert to two-phase dual-publish release model
Replace publish-on-push with the ProjectTemplate/LanguageTags two-phase
model: PRs smoke-test only, and publish-release.yml publishes both branches
on a weekly schedule (Mon 02:00 UTC) or manual dispatch, with idempotent
no-op republish. Adopt the reusable workflow set (get-version,
build-nugetlibrary, build-release, build-datebadge), a branch-aware
Dependabot merge-bot, Central Package Management, and an AGENTS.md tracking
the template. NuGet.org-only (drop GitHub Packages); no Docker/exe/PyPI/codegen.
Reconcile the template's strict analyzers (AnalysisMode All +
TreatWarningsAsErrors) with the brownfield library by relaxing specific
rules in .editorconfig and IL3058 via NoWarn, all documented.
* Normalize line endings to .editorconfig; fix husky hook
Convert the workflow YAML, dependabot.yml, and AGENTS.md (added LF) to CRLF
per .editorconfig, and make .husky/pre-commit LF + executable so its shebang
execs on Linux/WSL. Add an .editorconfig rule pinning the hook to LF.
* Quote "$GITHUB_OUTPUT" in date-badge task
Resolve the one-time old->new structural conflicts in develop's favour
(new reusable workflows, CPM, AGENTS.md, reformatting) and take the max
dependency/tool versions so main's newer Dependabot bumps are not regressed
(SourceLink 10.0.201, Serilog 4.3.1, Microsoft.NET.Test.Sdk 18.4.0,
xunit.analyzers 1.27.0, csharpier 1.2.6, husky 0.9.1).
CopilotAI review requested due to automatic review settings June 5, 2026 02:26

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Promotes the repository to the two-phase, dual-publish release model on main, aligning CI/CD, dependency management, and repo process documentation with the template-driven structure introduced on develop (with select version reconciliations to avoid regressing Dependabot bumps).

Changes:

  • Introduces the new CI/CD workflow set (PR smoke-test + scheduled/manual publish + Dependabot merge-bot) and removes the legacy publish + dependabot automerge workflows.
  • Switches to Central Package Management (Directory.Build.props + Directory.Packages.props) and updates project files accordingly (incl. IL3058 suppression for AOT projects).
  • Adds/updates repo process & configuration files (AGENTS.md, .editorconfig husky LF rule, .gitignore, README badge, solution items).

Reviewed changes

Copilot reviewed 38 out of 40 changed files in this pull request and generated 4 comments.

Show a summary per file
FileDescription
UtilitiesTests/UtilitiesTests.csprojMoves package versions to central management.
UtilitiesTests/UtilitiesTests.csRemoves now-redundant usings (implicit usings).
UtilitiesTests/StringHistoryTests.csRemoves now-redundant usings.
UtilitiesTests/StringCompressionTests.csRemoves now-redundant usings.
UtilitiesTests/StringCompressionAsyncTests.csRemoves now-redundant usings.
UtilitiesTests/FileExAsyncTests.csRemoves now-redundant usings.
UtilitiesTests/ExtensionsTests.csAdjusts null-handling tests; trims usings.
UtilitiesTests/DownloadTests.csRemoves now-redundant usings.
UtilitiesTests/DownloadAsyncTests.csRemoves now-redundant usings.
UtilitiesTests/ConsoleTests.csRemoves now-redundant usings.
Utilities/Utilities.csprojCentralizes TF/analyzers; suppresses IL3058; packable.
Utilities/StringHistory.csRemoves now-redundant usings.
Utilities/StringCompression.csRemoves now-redundant usings.
Utilities/Format.csRemoves now-redundant usings.
Utilities/FileExOptions.csRemoves now-redundant usings.
Utilities/FileEx.csRemoves now-redundant usings.
Utilities/Extensions.csRemoves now-redundant usings.
Utilities/Download.csRemoves now-redundant usings.
Utilities/ConsoleEx.csRemoves now-redundant usings.
Utilities/CommandLineEx.csRemoves now-redundant usings.
Utilities.slnxAdds new solution items + workflow files.
Sandbox/Sandbox.csprojCentralizes packages; suppresses IL3058.
Sandbox/Program.csMinor cleanup (AppContext usage).
README.mdUpdates workflow status badge to new workflow.
Directory.Packages.propsAdds centralized package versions.
Directory.Build.propsAdds shared build properties/analyzer strictness.
AGENTS.mdDocuments branching/release/workflow conventions.
.husky/pre-commitNormalizes hook file (LF/shebang handling).
.gitignoreIgnores .artifacts output directory.
.github/workflows/test-pull-request.ymlNew PR test/smoke build workflow + required-check aggregator.
.github/workflows/publish-release.ymlNew scheduled/manual publisher with two-phase gating.
.github/workflows/merge-bot-pull-request.ymlNew Dependabot merge-bot using app token + branch-aware merge method.
.github/workflows/get-version-task.ymlNew reusable NBGV version task.
.github/workflows/build-release-task.ymlNew orchestrator reusable workflow (build + optional publish).
.github/workflows/build-nugetlibrary-task.ymlNew reusable NuGet build/push task with artifacts.
.github/workflows/build-datebadge-task.ymlNew reusable BYOB date badge task.
.github/workflows/DependabotAutoMerge.ymlRemoves legacy Dependabot auto-merge workflow.
.github/workflows/BuildPublishPipeline.ymlRemoves legacy publish-on-push workflow.
.github/dependabot.ymlDuplicates ecosystems per-branch (main/develop).
.editorconfigAdds Husky hook LF rule + analyzer relaxations.

Comment threadUtilitiesTests/ExtensionsTests.cs
Comment threadUtilitiesTests/ExtensionsTests.cs
Comment threadUtilitiesTests/ExtensionsTests.cs
Comment thread.github/workflows/build-datebadge-task.yml
ptr727 added a commit that referenced this pull request Jun 5, 2026
## Summary
Land the two-phase dual-publish model on `main`, with **fully signed &
GitHub-verified history**. This is `main` merged with `develop`
(`0f1616d`), the one-time old→new structural conflicts resolved in
**develop's favour**, and the **max dependency/tool versions** taken so
`main`'s newer Dependabot bumps are not regressed.
All introduced commits are committer = `Pieter Viljoen
<ptr727@users.noreply.github.com>` and verified, satisfying
`required_signatures` (supersedes #322/#323, which carried unverifiable
web-flow-committed history).
### Dependency reconciliation (max of develop/main)
| Package / tool | Version |
| --- | --- |
| Microsoft.SourceLink.GitHub | 10.0.201 |
| Serilog | 4.3.1 |
| Microsoft.NET.Test.Sdk | 18.4.0 |
| xunit.analyzers | 1.27.0 |
| csharpier (tool) | 1.2.6 |
| husky (tool) | 0.9.1 |
Net diff vs `develop` is only the six version bumps above. See #320 for
the full change description.
## Maintainer follow-ups (after merge)
- Add `CODEGEN_APP_CLIENT_ID` / `CODEGEN_APP_PRIVATE_KEY` (GitHub App)
to **both** Actions and Dependabot secret stores for the merge-bot.
- Let Dependabot bring `develop`'s deps up to match (or open a small
sync PR).
- Kick off the first publish via **Actions → publish-release.yml → Run
workflow** once secrets are in.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
@ptr727ptr727 closed this Jun 5, 2026
@ptr727
ptr727 deleted the release/dualpublish branch June 5, 2026 13:13
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@ptr727