Release: two-phase dual-publish release model - #324

Merged
ptr727 merged 32 commits into
mainfrom
release/main
Jun 5, 2026
Merged

Release: two-phase dual-publish release model#324
ptr727 merged 32 commits into
mainfrom
release/main

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Summary

Land the two-phase dual-publish model on main, with fully signed & GitHub-verified history. This is main merged with develop (0f1616d), the one-time old→new structural conflicts resolved in develop's favour, and the max dependency/tool versions taken so main's newer Dependabot bumps are not regressed.

All introduced commits are committer = Pieter Viljoen <ptr727@users.noreply.github.com> and verified, satisfying required_signatures (supersedes #322/#323, which carried unverifiable web-flow-committed history).

Dependency reconciliation (max of develop/main)

Package / toolVersion
Microsoft.SourceLink.GitHub10.0.201
Serilog4.3.1
Microsoft.NET.Test.Sdk18.4.0
xunit.analyzers1.27.0
csharpier (tool)1.2.6
husky (tool)0.9.1

Net diff vs develop is only the six version bumps above. See #320 for the full change description.

Maintainer follow-ups (after merge)

  • Add CODEGEN_APP_CLIENT_ID / CODEGEN_APP_PRIVATE_KEY (GitHub App) to both Actions and Dependabot secret stores for the merge-bot.
  • Let Dependabot bring develop's deps up to match (or open a small sync PR).
  • Kick off the first publish via Actions → publish-release.yml → Run workflow once secrets are in.

🤖 Generated with Claude Code

dependabotBotand others added 30 commits August 19, 2025 20:51
Bumps csharpier from 1.1.1 to 1.1.2
Bumps xunit.analyzers from 1.23.0 to 1.24.0
Bumps xunit.runner.visualstudio from 3.1.3 to 3.1.4
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.1.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
- dependency-name: xunit.analyzers
dependency-version: 1.24.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
- dependency-name: xunit.runner.visualstudio
dependency-version: 3.1.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-0259308462
Bump the nuget-deps group with 3 updates
Bumps xunit.runner.visualstudio from 3.1.4 to 3.1.5
---
updated-dependencies:
- dependency-name: xunit.runner.visualstudio
dependency-version: 3.1.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…evelop/nuget-deps-6aadeae1b1
Bump the nuget-deps group with 1 update
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-39349b7924
Bump csharpier from 1.1.2 to 1.2.1
---
updated-dependencies:
- dependency-name: Serilog.Sinks.Console
dependency-version: 6.1.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…nuget-deps-602f419b37
Bump Serilog.Sinks.Console from 6.0.0 to 6.1.1
Bumps csharpier from 1.2.1 to 1.2.3
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-1689e99d0a
Bump the nuget-deps group with 1 update
Bumps the actions-deps group with 2 updates in the / directory: [actions/setup-dotnet](https://github.com/actions/setup-dotnet) and [actions/checkout](https://github.com/actions/checkout).
Updates `actions/setup-dotnet` from 4 to 5
- [Release notes](https://github.com/actions/setup-dotnet/releases)
- [Commits](actions/setup-dotnet@v4...v5)
Updates `actions/checkout` from 5 to 6
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v5...v6)
---
updated-dependencies:
- dependency-name: actions/setup-dotnet
dependency-version: '5'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
- dependency-name: actions/checkout
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps csharpier from 1.2.3 to 1.2.4
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-133b2bc611
Bump the nuget-deps group with 1 update
Bumps csharpier from 1.2.4 to 1.2.5
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-262ca43251
Bump the nuget-deps group with 1 update
* Initial plan
* Add using statement and simplify CallerMemberName attributes
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
* Initial plan
* Make HttpClient timeout configurable via TimeoutSeconds property
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Initial plan
* Replace redundant ToString() with string interpolation in FileExAsyncTests
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
* Initial plan
* Replace explicit ToString() calls with string interpolation
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
…304)
Bumps the actions-deps group with 1 update: [dependabot/fetch-metadata](https://github.com/dependabot/fetch-metadata).
Updates `dependabot/fetch-metadata` from 2 to 3
- [Release notes](https://github.com/dependabot/fetch-metadata/releases)
- [Commits](dependabot/fetch-metadata@v2...v3)
---
updated-dependencies:
- dependency-name: dependabot/fetch-metadata
dependency-version: '3'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
ptr727 added 2 commits June 4, 2026 18:28
* Convert to two-phase dual-publish release model
Replace publish-on-push with the ProjectTemplate/LanguageTags two-phase
model: PRs smoke-test only, and publish-release.yml publishes both branches
on a weekly schedule (Mon 02:00 UTC) or manual dispatch, with idempotent
no-op republish. Adopt the reusable workflow set (get-version,
build-nugetlibrary, build-release, build-datebadge), a branch-aware
Dependabot merge-bot, Central Package Management, and an AGENTS.md tracking
the template. NuGet.org-only (drop GitHub Packages); no Docker/exe/PyPI/codegen.
Reconcile the template's strict analyzers (AnalysisMode All +
TreatWarningsAsErrors) with the brownfield library by relaxing specific
rules in .editorconfig and IL3058 via NoWarn, all documented.
* Normalize line endings to .editorconfig; fix husky hook
Convert the workflow YAML, dependabot.yml, and AGENTS.md (added LF) to CRLF
per .editorconfig, and make .husky/pre-commit LF + executable so its shebang
execs on Linux/WSL. Add an .editorconfig rule pinning the hook to LF.
* Quote "$GITHUB_OUTPUT" in date-badge task
Resolve the one-time old->new structural conflicts in develop's favour and
take the max dependency/tool versions so main's newer Dependabot bumps are
not regressed (SourceLink 10.0.201, Serilog 4.3.1, Microsoft.NET.Test.Sdk
18.4.0, xunit.analyzers 1.27.0, csharpier 1.2.6, husky 0.9.1).
CopilotAI review requested due to automatic review settings June 5, 2026 13:07

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR lands the repo’s two-phase dual-publish release model onto main, aligning CI/release automation, Dependabot automation, and build configuration with the template-based workflow structure while reconciling dependency/tool versions via Central Package Management.

Changes:

  • Introduces new GitHub Actions workflow set for PR testing (unit tests + gated smoke build) and scheduled/manual publishing for both main and develop, plus a GitHub App–token-based merge-bot for Dependabot.
  • Moves shared build settings and package versions into Directory.Build.props and Directory.Packages.props, updating projects to use central package versions and tightening analyzer configuration.
  • Updates repo docs/config (AGENTS.md, README badge, .editorconfig/.gitignore, Husky hook) to match the new workflow and build conventions.

Reviewed changes

Copilot reviewed 38 out of 40 changed files in this pull request and generated 3 comments.

Show a summary per file
FileDescription
UtilitiesTests/UtilitiesTests.csprojDrops per-project framework/analyzer/package versions in favor of centralized props/package management.
UtilitiesTests/UtilitiesTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/StringHistoryTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/StringCompressionTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/StringCompressionAsyncTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/FileExAsyncTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/ExtensionsTests.csAdjusts null-handling tests and cleans up usings (but see review comments re: nullable warnings-as-errors).
UtilitiesTests/DownloadTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/DownloadAsyncTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/ConsoleTests.csRemoves now-redundant using directives under implicit usings.
Utilities/Utilities.csprojCentralizes core properties; adds IL3058 suppression for AOT-related warning and ensures packability.
Utilities/StringHistory.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/StringCompression.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/Format.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/FileExOptions.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/FileEx.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/Extensions.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/Download.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/ConsoleEx.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/CommandLineEx.csRemoves explicit usings now covered by implicit/global configuration.
Utilities.slnxAdds new solution items and updates workflow file references to the new model.
Sandbox/Sandbox.csprojCentralizes properties; adds IL3058 suppression and uses centrally managed package versions.
Sandbox/Program.csMinor cleanup (uses AppContext.BaseDirectory) and removes redundant using.
README.mdUpdates workflow badge to point at the new publishing workflow file.
Directory.Packages.propsIntroduces Central Package Management versions for dependencies/tools used across projects.
Directory.Build.propsIntroduces shared build properties (TFM, analyzers, warnings-as-errors, artifacts path, CPM enablement).
AGENTS.mdDocuments the new branching/release/workflow conventions and automation expectations.
.husky/pre-commitNormalizes formatting while keeping Husky hook behavior the same.
.gitignoreIgnores .artifacts directory used by the new shared build configuration.
.github/workflows/test-pull-request.ymlAdds PR workflow: unit tests + gated smoke build + required status aggregator job.
.github/workflows/publish-release.ymlAdds scheduled/manual (and optional push) publishing workflow with serialized concurrency and branch matrix.
.github/workflows/merge-bot-pull-request.ymlAdds Dependabot merge-bot using GitHub App token and branch-aware merge method.
.github/workflows/get-version-task.ymlAdds reusable NBGV version computation workflow for downstream build/publish tasks.
.github/workflows/DependabotAutoMerge.ymlRemoves legacy Dependabot auto-merge workflow.
.github/workflows/BuildPublishPipeline.ymlRemoves legacy build/publish pipeline workflow.
.github/workflows/build-release-task.ymlAdds reusable orchestrator workflow tying together versioning, build, NuGet push, and GitHub release creation.
.github/workflows/build-nugetlibrary-task.ymlAdds reusable workflow to build/package the library, optionally push to NuGet, and upload artifacts.
.github/workflows/build-datebadge-task.ymlAdds reusable workflow to generate/update a date badge (main-gated).
.github/dependabot.ymlReworks Dependabot config to target both main and develop across ecosystems.
.editorconfigAdds LF override for Husky hook file and documents analyzer severity relaxations for brownfield code.

Comment threadUtilitiesTests/ExtensionsTests.cs
Comment threadUtilitiesTests/ExtensionsTests.cs
Comment threadUtilitiesTests/ExtensionsTests.cs
@ptr727
ptr727 merged commit ed0d817 into mainJun 5, 2026
8 checks passed
@ptr727
ptr727 deleted the release/main branch June 5, 2026 13:13
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Release: two-phase dual-publish release model - #324

Merged
ptr727 merged 32 commits into
mainfrom
release/main
Jun 5, 2026
Merged

Release: two-phase dual-publish release model#324
ptr727 merged 32 commits into
mainfrom
release/main

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Summary

Land the two-phase dual-publish model on main, with fully signed & GitHub-verified history. This is main merged with develop (0f1616d), the one-time old→new structural conflicts resolved in develop's favour, and the max dependency/tool versions taken so main's newer Dependabot bumps are not regressed.

All introduced commits are committer = Pieter Viljoen <ptr727@users.noreply.github.com> and verified, satisfying required_signatures (supersedes #322/#323, which carried unverifiable web-flow-committed history).

Dependency reconciliation (max of develop/main)

Package / toolVersion
Microsoft.SourceLink.GitHub10.0.201
Serilog4.3.1
Microsoft.NET.Test.Sdk18.4.0
xunit.analyzers1.27.0
csharpier (tool)1.2.6
husky (tool)0.9.1

Net diff vs develop is only the six version bumps above. See #320 for the full change description.

Maintainer follow-ups (after merge)

  • Add CODEGEN_APP_CLIENT_ID / CODEGEN_APP_PRIVATE_KEY (GitHub App) to both Actions and Dependabot secret stores for the merge-bot.
  • Let Dependabot bring develop's deps up to match (or open a small sync PR).
  • Kick off the first publish via Actions → publish-release.yml → Run workflow once secrets are in.

🤖 Generated with Claude Code

dependabotBotand others added 30 commits August 19, 2025 20:51
Bumps csharpier from 1.1.1 to 1.1.2
Bumps xunit.analyzers from 1.23.0 to 1.24.0
Bumps xunit.runner.visualstudio from 3.1.3 to 3.1.4
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.1.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
- dependency-name: xunit.analyzers
dependency-version: 1.24.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
- dependency-name: xunit.runner.visualstudio
dependency-version: 3.1.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-0259308462
Bump the nuget-deps group with 3 updates
Bumps xunit.runner.visualstudio from 3.1.4 to 3.1.5
---
updated-dependencies:
- dependency-name: xunit.runner.visualstudio
dependency-version: 3.1.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…evelop/nuget-deps-6aadeae1b1
Bump the nuget-deps group with 1 update
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-39349b7924
Bump csharpier from 1.1.2 to 1.2.1
---
updated-dependencies:
- dependency-name: Serilog.Sinks.Console
dependency-version: 6.1.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…nuget-deps-602f419b37
Bump Serilog.Sinks.Console from 6.0.0 to 6.1.1
Bumps csharpier from 1.2.1 to 1.2.3
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-1689e99d0a
Bump the nuget-deps group with 1 update
Bumps the actions-deps group with 2 updates in the / directory: [actions/setup-dotnet](https://github.com/actions/setup-dotnet) and [actions/checkout](https://github.com/actions/checkout).
Updates `actions/setup-dotnet` from 4 to 5
- [Release notes](https://github.com/actions/setup-dotnet/releases)
- [Commits](actions/setup-dotnet@v4...v5)
Updates `actions/checkout` from 5 to 6
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v5...v6)
---
updated-dependencies:
- dependency-name: actions/setup-dotnet
dependency-version: '5'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
- dependency-name: actions/checkout
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps csharpier from 1.2.3 to 1.2.4
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-133b2bc611
Bump the nuget-deps group with 1 update
Bumps csharpier from 1.2.4 to 1.2.5
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-262ca43251
Bump the nuget-deps group with 1 update
* Initial plan
* Add using statement and simplify CallerMemberName attributes
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
* Initial plan
* Make HttpClient timeout configurable via TimeoutSeconds property
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Initial plan
* Replace redundant ToString() with string interpolation in FileExAsyncTests
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
* Initial plan
* Replace explicit ToString() calls with string interpolation
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
…304)
Bumps the actions-deps group with 1 update: [dependabot/fetch-metadata](https://github.com/dependabot/fetch-metadata).
Updates `dependabot/fetch-metadata` from 2 to 3
- [Release notes](https://github.com/dependabot/fetch-metadata/releases)
- [Commits](dependabot/fetch-metadata@v2...v3)
---
updated-dependencies:
- dependency-name: dependabot/fetch-metadata
dependency-version: '3'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
ptr727 added 2 commits June 4, 2026 18:28
* Convert to two-phase dual-publish release model
Replace publish-on-push with the ProjectTemplate/LanguageTags two-phase
model: PRs smoke-test only, and publish-release.yml publishes both branches
on a weekly schedule (Mon 02:00 UTC) or manual dispatch, with idempotent
no-op republish. Adopt the reusable workflow set (get-version,
build-nugetlibrary, build-release, build-datebadge), a branch-aware
Dependabot merge-bot, Central Package Management, and an AGENTS.md tracking
the template. NuGet.org-only (drop GitHub Packages); no Docker/exe/PyPI/codegen.
Reconcile the template's strict analyzers (AnalysisMode All +
TreatWarningsAsErrors) with the brownfield library by relaxing specific
rules in .editorconfig and IL3058 via NoWarn, all documented.
* Normalize line endings to .editorconfig; fix husky hook
Convert the workflow YAML, dependabot.yml, and AGENTS.md (added LF) to CRLF
per .editorconfig, and make .husky/pre-commit LF + executable so its shebang
execs on Linux/WSL. Add an .editorconfig rule pinning the hook to LF.
* Quote "$GITHUB_OUTPUT" in date-badge task
Resolve the one-time old->new structural conflicts in develop's favour and
take the max dependency/tool versions so main's newer Dependabot bumps are
not regressed (SourceLink 10.0.201, Serilog 4.3.1, Microsoft.NET.Test.Sdk
18.4.0, xunit.analyzers 1.27.0, csharpier 1.2.6, husky 0.9.1).
CopilotAI review requested due to automatic review settings June 5, 2026 13:07

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR lands the repo’s two-phase dual-publish release model onto main, aligning CI/release automation, Dependabot automation, and build configuration with the template-based workflow structure while reconciling dependency/tool versions via Central Package Management.

Changes:

  • Introduces new GitHub Actions workflow set for PR testing (unit tests + gated smoke build) and scheduled/manual publishing for both main and develop, plus a GitHub App–token-based merge-bot for Dependabot.
  • Moves shared build settings and package versions into Directory.Build.props and Directory.Packages.props, updating projects to use central package versions and tightening analyzer configuration.
  • Updates repo docs/config (AGENTS.md, README badge, .editorconfig/.gitignore, Husky hook) to match the new workflow and build conventions.

Reviewed changes

Copilot reviewed 38 out of 40 changed files in this pull request and generated 3 comments.

Show a summary per file
FileDescription
UtilitiesTests/UtilitiesTests.csprojDrops per-project framework/analyzer/package versions in favor of centralized props/package management.
UtilitiesTests/UtilitiesTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/StringHistoryTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/StringCompressionTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/StringCompressionAsyncTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/FileExAsyncTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/ExtensionsTests.csAdjusts null-handling tests and cleans up usings (but see review comments re: nullable warnings-as-errors).
UtilitiesTests/DownloadTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/DownloadAsyncTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/ConsoleTests.csRemoves now-redundant using directives under implicit usings.
Utilities/Utilities.csprojCentralizes core properties; adds IL3058 suppression for AOT-related warning and ensures packability.
Utilities/StringHistory.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/StringCompression.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/Format.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/FileExOptions.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/FileEx.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/Extensions.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/Download.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/ConsoleEx.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/CommandLineEx.csRemoves explicit usings now covered by implicit/global configuration.
Utilities.slnxAdds new solution items and updates workflow file references to the new model.
Sandbox/Sandbox.csprojCentralizes properties; adds IL3058 suppression and uses centrally managed package versions.
Sandbox/Program.csMinor cleanup (uses AppContext.BaseDirectory) and removes redundant using.
README.mdUpdates workflow badge to point at the new publishing workflow file.
Directory.Packages.propsIntroduces Central Package Management versions for dependencies/tools used across projects.
Directory.Build.propsIntroduces shared build properties (TFM, analyzers, warnings-as-errors, artifacts path, CPM enablement).
AGENTS.mdDocuments the new branching/release/workflow conventions and automation expectations.
.husky/pre-commitNormalizes formatting while keeping Husky hook behavior the same.
.gitignoreIgnores .artifacts directory used by the new shared build configuration.
.github/workflows/test-pull-request.ymlAdds PR workflow: unit tests + gated smoke build + required status aggregator job.
.github/workflows/publish-release.ymlAdds scheduled/manual (and optional push) publishing workflow with serialized concurrency and branch matrix.
.github/workflows/merge-bot-pull-request.ymlAdds Dependabot merge-bot using GitHub App token and branch-aware merge method.
.github/workflows/get-version-task.ymlAdds reusable NBGV version computation workflow for downstream build/publish tasks.
.github/workflows/DependabotAutoMerge.ymlRemoves legacy Dependabot auto-merge workflow.
.github/workflows/BuildPublishPipeline.ymlRemoves legacy build/publish pipeline workflow.
.github/workflows/build-release-task.ymlAdds reusable orchestrator workflow tying together versioning, build, NuGet push, and GitHub release creation.
.github/workflows/build-nugetlibrary-task.ymlAdds reusable workflow to build/package the library, optionally push to NuGet, and upload artifacts.
.github/workflows/build-datebadge-task.ymlAdds reusable workflow to generate/update a date badge (main-gated).
.github/dependabot.ymlReworks Dependabot config to target both main and develop across ecosystems.
.editorconfigAdds LF override for Husky hook file and documents analyzer severity relaxations for brownfield code.

Comment threadUtilitiesTests/ExtensionsTests.cs
Comment threadUtilitiesTests/ExtensionsTests.cs
Comment threadUtilitiesTests/ExtensionsTests.cs
@ptr727
ptr727 merged commit ed0d817 into mainJun 5, 2026
8 checks passed
@ptr727
ptr727 deleted the release/main branch June 5, 2026 13:13
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Release: two-phase dual-publish release model - #324

Merged
ptr727 merged 32 commits into
mainfrom
release/main
Jun 5, 2026
Merged

Release: two-phase dual-publish release model#324
ptr727 merged 32 commits into
mainfrom
release/main

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Summary

Land the two-phase dual-publish model on main, with fully signed & GitHub-verified history. This is main merged with develop (0f1616d), the one-time old→new structural conflicts resolved in develop's favour, and the max dependency/tool versions taken so main's newer Dependabot bumps are not regressed.

All introduced commits are committer = Pieter Viljoen <ptr727@users.noreply.github.com> and verified, satisfying required_signatures (supersedes #322/#323, which carried unverifiable web-flow-committed history).

Dependency reconciliation (max of develop/main)

Package / toolVersion
Microsoft.SourceLink.GitHub10.0.201
Serilog4.3.1
Microsoft.NET.Test.Sdk18.4.0
xunit.analyzers1.27.0
csharpier (tool)1.2.6
husky (tool)0.9.1

Net diff vs develop is only the six version bumps above. See #320 for the full change description.

Maintainer follow-ups (after merge)

  • Add CODEGEN_APP_CLIENT_ID / CODEGEN_APP_PRIVATE_KEY (GitHub App) to both Actions and Dependabot secret stores for the merge-bot.
  • Let Dependabot bring develop's deps up to match (or open a small sync PR).
  • Kick off the first publish via Actions → publish-release.yml → Run workflow once secrets are in.

🤖 Generated with Claude Code

dependabotBotand others added 30 commits August 19, 2025 20:51
Bumps csharpier from 1.1.1 to 1.1.2
Bumps xunit.analyzers from 1.23.0 to 1.24.0
Bumps xunit.runner.visualstudio from 3.1.3 to 3.1.4
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.1.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
- dependency-name: xunit.analyzers
dependency-version: 1.24.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
- dependency-name: xunit.runner.visualstudio
dependency-version: 3.1.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-0259308462
Bump the nuget-deps group with 3 updates
Bumps xunit.runner.visualstudio from 3.1.4 to 3.1.5
---
updated-dependencies:
- dependency-name: xunit.runner.visualstudio
dependency-version: 3.1.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…evelop/nuget-deps-6aadeae1b1
Bump the nuget-deps group with 1 update
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-39349b7924
Bump csharpier from 1.1.2 to 1.2.1
---
updated-dependencies:
- dependency-name: Serilog.Sinks.Console
dependency-version: 6.1.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…nuget-deps-602f419b37
Bump Serilog.Sinks.Console from 6.0.0 to 6.1.1
Bumps csharpier from 1.2.1 to 1.2.3
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-1689e99d0a
Bump the nuget-deps group with 1 update
Bumps the actions-deps group with 2 updates in the / directory: [actions/setup-dotnet](https://github.com/actions/setup-dotnet) and [actions/checkout](https://github.com/actions/checkout).
Updates `actions/setup-dotnet` from 4 to 5
- [Release notes](https://github.com/actions/setup-dotnet/releases)
- [Commits](actions/setup-dotnet@v4...v5)
Updates `actions/checkout` from 5 to 6
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v5...v6)
---
updated-dependencies:
- dependency-name: actions/setup-dotnet
dependency-version: '5'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
- dependency-name: actions/checkout
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps csharpier from 1.2.3 to 1.2.4
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-133b2bc611
Bump the nuget-deps group with 1 update
Bumps csharpier from 1.2.4 to 1.2.5
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-262ca43251
Bump the nuget-deps group with 1 update
* Initial plan
* Add using statement and simplify CallerMemberName attributes
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
* Initial plan
* Make HttpClient timeout configurable via TimeoutSeconds property
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Initial plan
* Replace redundant ToString() with string interpolation in FileExAsyncTests
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
* Initial plan
* Replace explicit ToString() calls with string interpolation
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
…304)
Bumps the actions-deps group with 1 update: [dependabot/fetch-metadata](https://github.com/dependabot/fetch-metadata).
Updates `dependabot/fetch-metadata` from 2 to 3
- [Release notes](https://github.com/dependabot/fetch-metadata/releases)
- [Commits](dependabot/fetch-metadata@v2...v3)
---
updated-dependencies:
- dependency-name: dependabot/fetch-metadata
dependency-version: '3'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
ptr727 added 2 commits June 4, 2026 18:28
* Convert to two-phase dual-publish release model
Replace publish-on-push with the ProjectTemplate/LanguageTags two-phase
model: PRs smoke-test only, and publish-release.yml publishes both branches
on a weekly schedule (Mon 02:00 UTC) or manual dispatch, with idempotent
no-op republish. Adopt the reusable workflow set (get-version,
build-nugetlibrary, build-release, build-datebadge), a branch-aware
Dependabot merge-bot, Central Package Management, and an AGENTS.md tracking
the template. NuGet.org-only (drop GitHub Packages); no Docker/exe/PyPI/codegen.
Reconcile the template's strict analyzers (AnalysisMode All +
TreatWarningsAsErrors) with the brownfield library by relaxing specific
rules in .editorconfig and IL3058 via NoWarn, all documented.
* Normalize line endings to .editorconfig; fix husky hook
Convert the workflow YAML, dependabot.yml, and AGENTS.md (added LF) to CRLF
per .editorconfig, and make .husky/pre-commit LF + executable so its shebang
execs on Linux/WSL. Add an .editorconfig rule pinning the hook to LF.
* Quote "$GITHUB_OUTPUT" in date-badge task
Resolve the one-time old->new structural conflicts in develop's favour and
take the max dependency/tool versions so main's newer Dependabot bumps are
not regressed (SourceLink 10.0.201, Serilog 4.3.1, Microsoft.NET.Test.Sdk
18.4.0, xunit.analyzers 1.27.0, csharpier 1.2.6, husky 0.9.1).
CopilotAI review requested due to automatic review settings June 5, 2026 13:07

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR lands the repo’s two-phase dual-publish release model onto main, aligning CI/release automation, Dependabot automation, and build configuration with the template-based workflow structure while reconciling dependency/tool versions via Central Package Management.

Changes:

  • Introduces new GitHub Actions workflow set for PR testing (unit tests + gated smoke build) and scheduled/manual publishing for both main and develop, plus a GitHub App–token-based merge-bot for Dependabot.
  • Moves shared build settings and package versions into Directory.Build.props and Directory.Packages.props, updating projects to use central package versions and tightening analyzer configuration.
  • Updates repo docs/config (AGENTS.md, README badge, .editorconfig/.gitignore, Husky hook) to match the new workflow and build conventions.

Reviewed changes

Copilot reviewed 38 out of 40 changed files in this pull request and generated 3 comments.

Show a summary per file
FileDescription
UtilitiesTests/UtilitiesTests.csprojDrops per-project framework/analyzer/package versions in favor of centralized props/package management.
UtilitiesTests/UtilitiesTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/StringHistoryTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/StringCompressionTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/StringCompressionAsyncTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/FileExAsyncTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/ExtensionsTests.csAdjusts null-handling tests and cleans up usings (but see review comments re: nullable warnings-as-errors).
UtilitiesTests/DownloadTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/DownloadAsyncTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/ConsoleTests.csRemoves now-redundant using directives under implicit usings.
Utilities/Utilities.csprojCentralizes core properties; adds IL3058 suppression for AOT-related warning and ensures packability.
Utilities/StringHistory.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/StringCompression.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/Format.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/FileExOptions.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/FileEx.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/Extensions.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/Download.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/ConsoleEx.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/CommandLineEx.csRemoves explicit usings now covered by implicit/global configuration.
Utilities.slnxAdds new solution items and updates workflow file references to the new model.
Sandbox/Sandbox.csprojCentralizes properties; adds IL3058 suppression and uses centrally managed package versions.
Sandbox/Program.csMinor cleanup (uses AppContext.BaseDirectory) and removes redundant using.
README.mdUpdates workflow badge to point at the new publishing workflow file.
Directory.Packages.propsIntroduces Central Package Management versions for dependencies/tools used across projects.
Directory.Build.propsIntroduces shared build properties (TFM, analyzers, warnings-as-errors, artifacts path, CPM enablement).
AGENTS.mdDocuments the new branching/release/workflow conventions and automation expectations.
.husky/pre-commitNormalizes formatting while keeping Husky hook behavior the same.
.gitignoreIgnores .artifacts directory used by the new shared build configuration.
.github/workflows/test-pull-request.ymlAdds PR workflow: unit tests + gated smoke build + required status aggregator job.
.github/workflows/publish-release.ymlAdds scheduled/manual (and optional push) publishing workflow with serialized concurrency and branch matrix.
.github/workflows/merge-bot-pull-request.ymlAdds Dependabot merge-bot using GitHub App token and branch-aware merge method.
.github/workflows/get-version-task.ymlAdds reusable NBGV version computation workflow for downstream build/publish tasks.
.github/workflows/DependabotAutoMerge.ymlRemoves legacy Dependabot auto-merge workflow.
.github/workflows/BuildPublishPipeline.ymlRemoves legacy build/publish pipeline workflow.
.github/workflows/build-release-task.ymlAdds reusable orchestrator workflow tying together versioning, build, NuGet push, and GitHub release creation.
.github/workflows/build-nugetlibrary-task.ymlAdds reusable workflow to build/package the library, optionally push to NuGet, and upload artifacts.
.github/workflows/build-datebadge-task.ymlAdds reusable workflow to generate/update a date badge (main-gated).
.github/dependabot.ymlReworks Dependabot config to target both main and develop across ecosystems.
.editorconfigAdds LF override for Husky hook file and documents analyzer severity relaxations for brownfield code.

Comment threadUtilitiesTests/ExtensionsTests.cs
Comment threadUtilitiesTests/ExtensionsTests.cs
Comment threadUtilitiesTests/ExtensionsTests.cs
@ptr727
ptr727 merged commit ed0d817 into mainJun 5, 2026
8 checks passed
@ptr727
ptr727 deleted the release/main branch June 5, 2026 13:13
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Release: two-phase dual-publish release model - #324

Merged
ptr727 merged 32 commits into
mainfrom
release/main
Jun 5, 2026
Merged

Release: two-phase dual-publish release model#324
ptr727 merged 32 commits into
mainfrom
release/main

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Summary

Land the two-phase dual-publish model on main, with fully signed & GitHub-verified history. This is main merged with develop (0f1616d), the one-time old→new structural conflicts resolved in develop's favour, and the max dependency/tool versions taken so main's newer Dependabot bumps are not regressed.

All introduced commits are committer = Pieter Viljoen <ptr727@users.noreply.github.com> and verified, satisfying required_signatures (supersedes #322/#323, which carried unverifiable web-flow-committed history).

Dependency reconciliation (max of develop/main)

Package / toolVersion
Microsoft.SourceLink.GitHub10.0.201
Serilog4.3.1
Microsoft.NET.Test.Sdk18.4.0
xunit.analyzers1.27.0
csharpier (tool)1.2.6
husky (tool)0.9.1

Net diff vs develop is only the six version bumps above. See #320 for the full change description.

Maintainer follow-ups (after merge)

  • Add CODEGEN_APP_CLIENT_ID / CODEGEN_APP_PRIVATE_KEY (GitHub App) to both Actions and Dependabot secret stores for the merge-bot.
  • Let Dependabot bring develop's deps up to match (or open a small sync PR).
  • Kick off the first publish via Actions → publish-release.yml → Run workflow once secrets are in.

🤖 Generated with Claude Code

dependabotBotand others added 30 commits August 19, 2025 20:51
Bumps csharpier from 1.1.1 to 1.1.2
Bumps xunit.analyzers from 1.23.0 to 1.24.0
Bumps xunit.runner.visualstudio from 3.1.3 to 3.1.4
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.1.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
- dependency-name: xunit.analyzers
dependency-version: 1.24.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
- dependency-name: xunit.runner.visualstudio
dependency-version: 3.1.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-0259308462
Bump the nuget-deps group with 3 updates
Bumps xunit.runner.visualstudio from 3.1.4 to 3.1.5
---
updated-dependencies:
- dependency-name: xunit.runner.visualstudio
dependency-version: 3.1.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…evelop/nuget-deps-6aadeae1b1
Bump the nuget-deps group with 1 update
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-39349b7924
Bump csharpier from 1.1.2 to 1.2.1
---
updated-dependencies:
- dependency-name: Serilog.Sinks.Console
dependency-version: 6.1.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…nuget-deps-602f419b37
Bump Serilog.Sinks.Console from 6.0.0 to 6.1.1
Bumps csharpier from 1.2.1 to 1.2.3
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-1689e99d0a
Bump the nuget-deps group with 1 update
Bumps the actions-deps group with 2 updates in the / directory: [actions/setup-dotnet](https://github.com/actions/setup-dotnet) and [actions/checkout](https://github.com/actions/checkout).
Updates `actions/setup-dotnet` from 4 to 5
- [Release notes](https://github.com/actions/setup-dotnet/releases)
- [Commits](actions/setup-dotnet@v4...v5)
Updates `actions/checkout` from 5 to 6
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v5...v6)
---
updated-dependencies:
- dependency-name: actions/setup-dotnet
dependency-version: '5'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
- dependency-name: actions/checkout
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps csharpier from 1.2.3 to 1.2.4
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-133b2bc611
Bump the nuget-deps group with 1 update
Bumps csharpier from 1.2.4 to 1.2.5
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-262ca43251
Bump the nuget-deps group with 1 update
* Initial plan
* Add using statement and simplify CallerMemberName attributes
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
* Initial plan
* Make HttpClient timeout configurable via TimeoutSeconds property
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Initial plan
* Replace redundant ToString() with string interpolation in FileExAsyncTests
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
* Initial plan
* Replace explicit ToString() calls with string interpolation
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
…304)
Bumps the actions-deps group with 1 update: [dependabot/fetch-metadata](https://github.com/dependabot/fetch-metadata).
Updates `dependabot/fetch-metadata` from 2 to 3
- [Release notes](https://github.com/dependabot/fetch-metadata/releases)
- [Commits](dependabot/fetch-metadata@v2...v3)
---
updated-dependencies:
- dependency-name: dependabot/fetch-metadata
dependency-version: '3'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
ptr727 added 2 commits June 4, 2026 18:28
* Convert to two-phase dual-publish release model
Replace publish-on-push with the ProjectTemplate/LanguageTags two-phase
model: PRs smoke-test only, and publish-release.yml publishes both branches
on a weekly schedule (Mon 02:00 UTC) or manual dispatch, with idempotent
no-op republish. Adopt the reusable workflow set (get-version,
build-nugetlibrary, build-release, build-datebadge), a branch-aware
Dependabot merge-bot, Central Package Management, and an AGENTS.md tracking
the template. NuGet.org-only (drop GitHub Packages); no Docker/exe/PyPI/codegen.
Reconcile the template's strict analyzers (AnalysisMode All +
TreatWarningsAsErrors) with the brownfield library by relaxing specific
rules in .editorconfig and IL3058 via NoWarn, all documented.
* Normalize line endings to .editorconfig; fix husky hook
Convert the workflow YAML, dependabot.yml, and AGENTS.md (added LF) to CRLF
per .editorconfig, and make .husky/pre-commit LF + executable so its shebang
execs on Linux/WSL. Add an .editorconfig rule pinning the hook to LF.
* Quote "$GITHUB_OUTPUT" in date-badge task
Resolve the one-time old->new structural conflicts in develop's favour and
take the max dependency/tool versions so main's newer Dependabot bumps are
not regressed (SourceLink 10.0.201, Serilog 4.3.1, Microsoft.NET.Test.Sdk
18.4.0, xunit.analyzers 1.27.0, csharpier 1.2.6, husky 0.9.1).
CopilotAI review requested due to automatic review settings June 5, 2026 13:07

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR lands the repo’s two-phase dual-publish release model onto main, aligning CI/release automation, Dependabot automation, and build configuration with the template-based workflow structure while reconciling dependency/tool versions via Central Package Management.

Changes:

  • Introduces new GitHub Actions workflow set for PR testing (unit tests + gated smoke build) and scheduled/manual publishing for both main and develop, plus a GitHub App–token-based merge-bot for Dependabot.
  • Moves shared build settings and package versions into Directory.Build.props and Directory.Packages.props, updating projects to use central package versions and tightening analyzer configuration.
  • Updates repo docs/config (AGENTS.md, README badge, .editorconfig/.gitignore, Husky hook) to match the new workflow and build conventions.

Reviewed changes

Copilot reviewed 38 out of 40 changed files in this pull request and generated 3 comments.

Show a summary per file
FileDescription
UtilitiesTests/UtilitiesTests.csprojDrops per-project framework/analyzer/package versions in favor of centralized props/package management.
UtilitiesTests/UtilitiesTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/StringHistoryTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/StringCompressionTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/StringCompressionAsyncTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/FileExAsyncTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/ExtensionsTests.csAdjusts null-handling tests and cleans up usings (but see review comments re: nullable warnings-as-errors).
UtilitiesTests/DownloadTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/DownloadAsyncTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/ConsoleTests.csRemoves now-redundant using directives under implicit usings.
Utilities/Utilities.csprojCentralizes core properties; adds IL3058 suppression for AOT-related warning and ensures packability.
Utilities/StringHistory.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/StringCompression.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/Format.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/FileExOptions.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/FileEx.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/Extensions.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/Download.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/ConsoleEx.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/CommandLineEx.csRemoves explicit usings now covered by implicit/global configuration.
Utilities.slnxAdds new solution items and updates workflow file references to the new model.
Sandbox/Sandbox.csprojCentralizes properties; adds IL3058 suppression and uses centrally managed package versions.
Sandbox/Program.csMinor cleanup (uses AppContext.BaseDirectory) and removes redundant using.
README.mdUpdates workflow badge to point at the new publishing workflow file.
Directory.Packages.propsIntroduces Central Package Management versions for dependencies/tools used across projects.
Directory.Build.propsIntroduces shared build properties (TFM, analyzers, warnings-as-errors, artifacts path, CPM enablement).
AGENTS.mdDocuments the new branching/release/workflow conventions and automation expectations.
.husky/pre-commitNormalizes formatting while keeping Husky hook behavior the same.
.gitignoreIgnores .artifacts directory used by the new shared build configuration.
.github/workflows/test-pull-request.ymlAdds PR workflow: unit tests + gated smoke build + required status aggregator job.
.github/workflows/publish-release.ymlAdds scheduled/manual (and optional push) publishing workflow with serialized concurrency and branch matrix.
.github/workflows/merge-bot-pull-request.ymlAdds Dependabot merge-bot using GitHub App token and branch-aware merge method.
.github/workflows/get-version-task.ymlAdds reusable NBGV version computation workflow for downstream build/publish tasks.
.github/workflows/DependabotAutoMerge.ymlRemoves legacy Dependabot auto-merge workflow.
.github/workflows/BuildPublishPipeline.ymlRemoves legacy build/publish pipeline workflow.
.github/workflows/build-release-task.ymlAdds reusable orchestrator workflow tying together versioning, build, NuGet push, and GitHub release creation.
.github/workflows/build-nugetlibrary-task.ymlAdds reusable workflow to build/package the library, optionally push to NuGet, and upload artifacts.
.github/workflows/build-datebadge-task.ymlAdds reusable workflow to generate/update a date badge (main-gated).
.github/dependabot.ymlReworks Dependabot config to target both main and develop across ecosystems.
.editorconfigAdds LF override for Husky hook file and documents analyzer severity relaxations for brownfield code.

Comment threadUtilitiesTests/ExtensionsTests.cs
Comment threadUtilitiesTests/ExtensionsTests.cs
Comment threadUtilitiesTests/ExtensionsTests.cs
@ptr727
ptr727 merged commit ed0d817 into mainJun 5, 2026
8 checks passed
@ptr727
ptr727 deleted the release/main branch June 5, 2026 13:13
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Release: two-phase dual-publish release model - #324

Merged
ptr727 merged 32 commits into
mainfrom
release/main
Jun 5, 2026
Merged

Release: two-phase dual-publish release model#324
ptr727 merged 32 commits into
mainfrom
release/main

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Summary

Land the two-phase dual-publish model on main, with fully signed & GitHub-verified history. This is main merged with develop (0f1616d), the one-time old→new structural conflicts resolved in develop's favour, and the max dependency/tool versions taken so main's newer Dependabot bumps are not regressed.

All introduced commits are committer = Pieter Viljoen <ptr727@users.noreply.github.com> and verified, satisfying required_signatures (supersedes #322/#323, which carried unverifiable web-flow-committed history).

Dependency reconciliation (max of develop/main)

Package / toolVersion
Microsoft.SourceLink.GitHub10.0.201
Serilog4.3.1
Microsoft.NET.Test.Sdk18.4.0
xunit.analyzers1.27.0
csharpier (tool)1.2.6
husky (tool)0.9.1

Net diff vs develop is only the six version bumps above. See #320 for the full change description.

Maintainer follow-ups (after merge)

  • Add CODEGEN_APP_CLIENT_ID / CODEGEN_APP_PRIVATE_KEY (GitHub App) to both Actions and Dependabot secret stores for the merge-bot.
  • Let Dependabot bring develop's deps up to match (or open a small sync PR).
  • Kick off the first publish via Actions → publish-release.yml → Run workflow once secrets are in.

🤖 Generated with Claude Code

dependabotBotand others added 30 commits August 19, 2025 20:51
Bumps csharpier from 1.1.1 to 1.1.2
Bumps xunit.analyzers from 1.23.0 to 1.24.0
Bumps xunit.runner.visualstudio from 3.1.3 to 3.1.4
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.1.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
- dependency-name: xunit.analyzers
dependency-version: 1.24.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
- dependency-name: xunit.runner.visualstudio
dependency-version: 3.1.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-0259308462
Bump the nuget-deps group with 3 updates
Bumps xunit.runner.visualstudio from 3.1.4 to 3.1.5
---
updated-dependencies:
- dependency-name: xunit.runner.visualstudio
dependency-version: 3.1.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…evelop/nuget-deps-6aadeae1b1
Bump the nuget-deps group with 1 update
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-39349b7924
Bump csharpier from 1.1.2 to 1.2.1
---
updated-dependencies:
- dependency-name: Serilog.Sinks.Console
dependency-version: 6.1.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…nuget-deps-602f419b37
Bump Serilog.Sinks.Console from 6.0.0 to 6.1.1
Bumps csharpier from 1.2.1 to 1.2.3
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-1689e99d0a
Bump the nuget-deps group with 1 update
Bumps the actions-deps group with 2 updates in the / directory: [actions/setup-dotnet](https://github.com/actions/setup-dotnet) and [actions/checkout](https://github.com/actions/checkout).
Updates `actions/setup-dotnet` from 4 to 5
- [Release notes](https://github.com/actions/setup-dotnet/releases)
- [Commits](actions/setup-dotnet@v4...v5)
Updates `actions/checkout` from 5 to 6
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v5...v6)
---
updated-dependencies:
- dependency-name: actions/setup-dotnet
dependency-version: '5'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
- dependency-name: actions/checkout
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps csharpier from 1.2.3 to 1.2.4
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-133b2bc611
Bump the nuget-deps group with 1 update
Bumps csharpier from 1.2.4 to 1.2.5
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-262ca43251
Bump the nuget-deps group with 1 update
* Initial plan
* Add using statement and simplify CallerMemberName attributes
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
* Initial plan
* Make HttpClient timeout configurable via TimeoutSeconds property
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Initial plan
* Replace redundant ToString() with string interpolation in FileExAsyncTests
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
* Initial plan
* Replace explicit ToString() calls with string interpolation
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
…304)
Bumps the actions-deps group with 1 update: [dependabot/fetch-metadata](https://github.com/dependabot/fetch-metadata).
Updates `dependabot/fetch-metadata` from 2 to 3
- [Release notes](https://github.com/dependabot/fetch-metadata/releases)
- [Commits](dependabot/fetch-metadata@v2...v3)
---
updated-dependencies:
- dependency-name: dependabot/fetch-metadata
dependency-version: '3'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
ptr727 added 2 commits June 4, 2026 18:28
* Convert to two-phase dual-publish release model
Replace publish-on-push with the ProjectTemplate/LanguageTags two-phase
model: PRs smoke-test only, and publish-release.yml publishes both branches
on a weekly schedule (Mon 02:00 UTC) or manual dispatch, with idempotent
no-op republish. Adopt the reusable workflow set (get-version,
build-nugetlibrary, build-release, build-datebadge), a branch-aware
Dependabot merge-bot, Central Package Management, and an AGENTS.md tracking
the template. NuGet.org-only (drop GitHub Packages); no Docker/exe/PyPI/codegen.
Reconcile the template's strict analyzers (AnalysisMode All +
TreatWarningsAsErrors) with the brownfield library by relaxing specific
rules in .editorconfig and IL3058 via NoWarn, all documented.
* Normalize line endings to .editorconfig; fix husky hook
Convert the workflow YAML, dependabot.yml, and AGENTS.md (added LF) to CRLF
per .editorconfig, and make .husky/pre-commit LF + executable so its shebang
execs on Linux/WSL. Add an .editorconfig rule pinning the hook to LF.
* Quote "$GITHUB_OUTPUT" in date-badge task
Resolve the one-time old->new structural conflicts in develop's favour and
take the max dependency/tool versions so main's newer Dependabot bumps are
not regressed (SourceLink 10.0.201, Serilog 4.3.1, Microsoft.NET.Test.Sdk
18.4.0, xunit.analyzers 1.27.0, csharpier 1.2.6, husky 0.9.1).
CopilotAI review requested due to automatic review settings June 5, 2026 13:07

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR lands the repo’s two-phase dual-publish release model onto main, aligning CI/release automation, Dependabot automation, and build configuration with the template-based workflow structure while reconciling dependency/tool versions via Central Package Management.

Changes:

  • Introduces new GitHub Actions workflow set for PR testing (unit tests + gated smoke build) and scheduled/manual publishing for both main and develop, plus a GitHub App–token-based merge-bot for Dependabot.
  • Moves shared build settings and package versions into Directory.Build.props and Directory.Packages.props, updating projects to use central package versions and tightening analyzer configuration.
  • Updates repo docs/config (AGENTS.md, README badge, .editorconfig/.gitignore, Husky hook) to match the new workflow and build conventions.

Reviewed changes

Copilot reviewed 38 out of 40 changed files in this pull request and generated 3 comments.

Show a summary per file
FileDescription
UtilitiesTests/UtilitiesTests.csprojDrops per-project framework/analyzer/package versions in favor of centralized props/package management.
UtilitiesTests/UtilitiesTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/StringHistoryTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/StringCompressionTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/StringCompressionAsyncTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/FileExAsyncTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/ExtensionsTests.csAdjusts null-handling tests and cleans up usings (but see review comments re: nullable warnings-as-errors).
UtilitiesTests/DownloadTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/DownloadAsyncTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/ConsoleTests.csRemoves now-redundant using directives under implicit usings.
Utilities/Utilities.csprojCentralizes core properties; adds IL3058 suppression for AOT-related warning and ensures packability.
Utilities/StringHistory.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/StringCompression.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/Format.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/FileExOptions.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/FileEx.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/Extensions.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/Download.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/ConsoleEx.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/CommandLineEx.csRemoves explicit usings now covered by implicit/global configuration.
Utilities.slnxAdds new solution items and updates workflow file references to the new model.
Sandbox/Sandbox.csprojCentralizes properties; adds IL3058 suppression and uses centrally managed package versions.
Sandbox/Program.csMinor cleanup (uses AppContext.BaseDirectory) and removes redundant using.
README.mdUpdates workflow badge to point at the new publishing workflow file.
Directory.Packages.propsIntroduces Central Package Management versions for dependencies/tools used across projects.
Directory.Build.propsIntroduces shared build properties (TFM, analyzers, warnings-as-errors, artifacts path, CPM enablement).
AGENTS.mdDocuments the new branching/release/workflow conventions and automation expectations.
.husky/pre-commitNormalizes formatting while keeping Husky hook behavior the same.
.gitignoreIgnores .artifacts directory used by the new shared build configuration.
.github/workflows/test-pull-request.ymlAdds PR workflow: unit tests + gated smoke build + required status aggregator job.
.github/workflows/publish-release.ymlAdds scheduled/manual (and optional push) publishing workflow with serialized concurrency and branch matrix.
.github/workflows/merge-bot-pull-request.ymlAdds Dependabot merge-bot using GitHub App token and branch-aware merge method.
.github/workflows/get-version-task.ymlAdds reusable NBGV version computation workflow for downstream build/publish tasks.
.github/workflows/DependabotAutoMerge.ymlRemoves legacy Dependabot auto-merge workflow.
.github/workflows/BuildPublishPipeline.ymlRemoves legacy build/publish pipeline workflow.
.github/workflows/build-release-task.ymlAdds reusable orchestrator workflow tying together versioning, build, NuGet push, and GitHub release creation.
.github/workflows/build-nugetlibrary-task.ymlAdds reusable workflow to build/package the library, optionally push to NuGet, and upload artifacts.
.github/workflows/build-datebadge-task.ymlAdds reusable workflow to generate/update a date badge (main-gated).
.github/dependabot.ymlReworks Dependabot config to target both main and develop across ecosystems.
.editorconfigAdds LF override for Husky hook file and documents analyzer severity relaxations for brownfield code.

Comment threadUtilitiesTests/ExtensionsTests.cs
Comment threadUtilitiesTests/ExtensionsTests.cs
Comment threadUtilitiesTests/ExtensionsTests.cs
@ptr727
ptr727 merged commit ed0d817 into mainJun 5, 2026
8 checks passed
@ptr727
ptr727 deleted the release/main branch June 5, 2026 13:13
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Release: two-phase dual-publish release model - #324

Merged
ptr727 merged 32 commits into
mainfrom
release/main
Jun 5, 2026
Merged

Release: two-phase dual-publish release model#324
ptr727 merged 32 commits into
mainfrom
release/main

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Summary

Land the two-phase dual-publish model on main, with fully signed & GitHub-verified history. This is main merged with develop (0f1616d), the one-time old→new structural conflicts resolved in develop's favour, and the max dependency/tool versions taken so main's newer Dependabot bumps are not regressed.

All introduced commits are committer = Pieter Viljoen <ptr727@users.noreply.github.com> and verified, satisfying required_signatures (supersedes #322/#323, which carried unverifiable web-flow-committed history).

Dependency reconciliation (max of develop/main)

Package / toolVersion
Microsoft.SourceLink.GitHub10.0.201
Serilog4.3.1
Microsoft.NET.Test.Sdk18.4.0
xunit.analyzers1.27.0
csharpier (tool)1.2.6
husky (tool)0.9.1

Net diff vs develop is only the six version bumps above. See #320 for the full change description.

Maintainer follow-ups (after merge)

  • Add CODEGEN_APP_CLIENT_ID / CODEGEN_APP_PRIVATE_KEY (GitHub App) to both Actions and Dependabot secret stores for the merge-bot.
  • Let Dependabot bring develop's deps up to match (or open a small sync PR).
  • Kick off the first publish via Actions → publish-release.yml → Run workflow once secrets are in.

🤖 Generated with Claude Code

dependabotBotand others added 30 commits August 19, 2025 20:51
Bumps csharpier from 1.1.1 to 1.1.2
Bumps xunit.analyzers from 1.23.0 to 1.24.0
Bumps xunit.runner.visualstudio from 3.1.3 to 3.1.4
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.1.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
- dependency-name: xunit.analyzers
dependency-version: 1.24.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
- dependency-name: xunit.runner.visualstudio
dependency-version: 3.1.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-0259308462
Bump the nuget-deps group with 3 updates
Bumps xunit.runner.visualstudio from 3.1.4 to 3.1.5
---
updated-dependencies:
- dependency-name: xunit.runner.visualstudio
dependency-version: 3.1.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…evelop/nuget-deps-6aadeae1b1
Bump the nuget-deps group with 1 update
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-39349b7924
Bump csharpier from 1.1.2 to 1.2.1
---
updated-dependencies:
- dependency-name: Serilog.Sinks.Console
dependency-version: 6.1.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…nuget-deps-602f419b37
Bump Serilog.Sinks.Console from 6.0.0 to 6.1.1
Bumps csharpier from 1.2.1 to 1.2.3
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-1689e99d0a
Bump the nuget-deps group with 1 update
Bumps the actions-deps group with 2 updates in the / directory: [actions/setup-dotnet](https://github.com/actions/setup-dotnet) and [actions/checkout](https://github.com/actions/checkout).
Updates `actions/setup-dotnet` from 4 to 5
- [Release notes](https://github.com/actions/setup-dotnet/releases)
- [Commits](actions/setup-dotnet@v4...v5)
Updates `actions/checkout` from 5 to 6
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v5...v6)
---
updated-dependencies:
- dependency-name: actions/setup-dotnet
dependency-version: '5'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
- dependency-name: actions/checkout
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps csharpier from 1.2.3 to 1.2.4
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-133b2bc611
Bump the nuget-deps group with 1 update
Bumps csharpier from 1.2.4 to 1.2.5
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-262ca43251
Bump the nuget-deps group with 1 update
* Initial plan
* Add using statement and simplify CallerMemberName attributes
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
* Initial plan
* Make HttpClient timeout configurable via TimeoutSeconds property
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Initial plan
* Replace redundant ToString() with string interpolation in FileExAsyncTests
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
* Initial plan
* Replace explicit ToString() calls with string interpolation
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
…304)
Bumps the actions-deps group with 1 update: [dependabot/fetch-metadata](https://github.com/dependabot/fetch-metadata).
Updates `dependabot/fetch-metadata` from 2 to 3
- [Release notes](https://github.com/dependabot/fetch-metadata/releases)
- [Commits](dependabot/fetch-metadata@v2...v3)
---
updated-dependencies:
- dependency-name: dependabot/fetch-metadata
dependency-version: '3'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
ptr727 added 2 commits June 4, 2026 18:28
* Convert to two-phase dual-publish release model
Replace publish-on-push with the ProjectTemplate/LanguageTags two-phase
model: PRs smoke-test only, and publish-release.yml publishes both branches
on a weekly schedule (Mon 02:00 UTC) or manual dispatch, with idempotent
no-op republish. Adopt the reusable workflow set (get-version,
build-nugetlibrary, build-release, build-datebadge), a branch-aware
Dependabot merge-bot, Central Package Management, and an AGENTS.md tracking
the template. NuGet.org-only (drop GitHub Packages); no Docker/exe/PyPI/codegen.
Reconcile the template's strict analyzers (AnalysisMode All +
TreatWarningsAsErrors) with the brownfield library by relaxing specific
rules in .editorconfig and IL3058 via NoWarn, all documented.
* Normalize line endings to .editorconfig; fix husky hook
Convert the workflow YAML, dependabot.yml, and AGENTS.md (added LF) to CRLF
per .editorconfig, and make .husky/pre-commit LF + executable so its shebang
execs on Linux/WSL. Add an .editorconfig rule pinning the hook to LF.
* Quote "$GITHUB_OUTPUT" in date-badge task
Resolve the one-time old->new structural conflicts in develop's favour and
take the max dependency/tool versions so main's newer Dependabot bumps are
not regressed (SourceLink 10.0.201, Serilog 4.3.1, Microsoft.NET.Test.Sdk
18.4.0, xunit.analyzers 1.27.0, csharpier 1.2.6, husky 0.9.1).
CopilotAI review requested due to automatic review settings June 5, 2026 13:07

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR lands the repo’s two-phase dual-publish release model onto main, aligning CI/release automation, Dependabot automation, and build configuration with the template-based workflow structure while reconciling dependency/tool versions via Central Package Management.

Changes:

  • Introduces new GitHub Actions workflow set for PR testing (unit tests + gated smoke build) and scheduled/manual publishing for both main and develop, plus a GitHub App–token-based merge-bot for Dependabot.
  • Moves shared build settings and package versions into Directory.Build.props and Directory.Packages.props, updating projects to use central package versions and tightening analyzer configuration.
  • Updates repo docs/config (AGENTS.md, README badge, .editorconfig/.gitignore, Husky hook) to match the new workflow and build conventions.

Reviewed changes

Copilot reviewed 38 out of 40 changed files in this pull request and generated 3 comments.

Show a summary per file
FileDescription
UtilitiesTests/UtilitiesTests.csprojDrops per-project framework/analyzer/package versions in favor of centralized props/package management.
UtilitiesTests/UtilitiesTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/StringHistoryTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/StringCompressionTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/StringCompressionAsyncTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/FileExAsyncTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/ExtensionsTests.csAdjusts null-handling tests and cleans up usings (but see review comments re: nullable warnings-as-errors).
UtilitiesTests/DownloadTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/DownloadAsyncTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/ConsoleTests.csRemoves now-redundant using directives under implicit usings.
Utilities/Utilities.csprojCentralizes core properties; adds IL3058 suppression for AOT-related warning and ensures packability.
Utilities/StringHistory.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/StringCompression.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/Format.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/FileExOptions.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/FileEx.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/Extensions.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/Download.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/ConsoleEx.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/CommandLineEx.csRemoves explicit usings now covered by implicit/global configuration.
Utilities.slnxAdds new solution items and updates workflow file references to the new model.
Sandbox/Sandbox.csprojCentralizes properties; adds IL3058 suppression and uses centrally managed package versions.
Sandbox/Program.csMinor cleanup (uses AppContext.BaseDirectory) and removes redundant using.
README.mdUpdates workflow badge to point at the new publishing workflow file.
Directory.Packages.propsIntroduces Central Package Management versions for dependencies/tools used across projects.
Directory.Build.propsIntroduces shared build properties (TFM, analyzers, warnings-as-errors, artifacts path, CPM enablement).
AGENTS.mdDocuments the new branching/release/workflow conventions and automation expectations.
.husky/pre-commitNormalizes formatting while keeping Husky hook behavior the same.
.gitignoreIgnores .artifacts directory used by the new shared build configuration.
.github/workflows/test-pull-request.ymlAdds PR workflow: unit tests + gated smoke build + required status aggregator job.
.github/workflows/publish-release.ymlAdds scheduled/manual (and optional push) publishing workflow with serialized concurrency and branch matrix.
.github/workflows/merge-bot-pull-request.ymlAdds Dependabot merge-bot using GitHub App token and branch-aware merge method.
.github/workflows/get-version-task.ymlAdds reusable NBGV version computation workflow for downstream build/publish tasks.
.github/workflows/DependabotAutoMerge.ymlRemoves legacy Dependabot auto-merge workflow.
.github/workflows/BuildPublishPipeline.ymlRemoves legacy build/publish pipeline workflow.
.github/workflows/build-release-task.ymlAdds reusable orchestrator workflow tying together versioning, build, NuGet push, and GitHub release creation.
.github/workflows/build-nugetlibrary-task.ymlAdds reusable workflow to build/package the library, optionally push to NuGet, and upload artifacts.
.github/workflows/build-datebadge-task.ymlAdds reusable workflow to generate/update a date badge (main-gated).
.github/dependabot.ymlReworks Dependabot config to target both main and develop across ecosystems.
.editorconfigAdds LF override for Husky hook file and documents analyzer severity relaxations for brownfield code.

Comment threadUtilitiesTests/ExtensionsTests.cs
Comment threadUtilitiesTests/ExtensionsTests.cs
Comment threadUtilitiesTests/ExtensionsTests.cs
@ptr727
ptr727 merged commit ed0d817 into mainJun 5, 2026
8 checks passed
@ptr727
ptr727 deleted the release/main branch June 5, 2026 13:13
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Release: two-phase dual-publish release model - #324

Merged
ptr727 merged 32 commits into
mainfrom
release/main
Jun 5, 2026
Merged

Release: two-phase dual-publish release model#324
ptr727 merged 32 commits into
mainfrom
release/main

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Summary

Land the two-phase dual-publish model on main, with fully signed & GitHub-verified history. This is main merged with develop (0f1616d), the one-time old→new structural conflicts resolved in develop's favour, and the max dependency/tool versions taken so main's newer Dependabot bumps are not regressed.

All introduced commits are committer = Pieter Viljoen <ptr727@users.noreply.github.com> and verified, satisfying required_signatures (supersedes #322/#323, which carried unverifiable web-flow-committed history).

Dependency reconciliation (max of develop/main)

Package / toolVersion
Microsoft.SourceLink.GitHub10.0.201
Serilog4.3.1
Microsoft.NET.Test.Sdk18.4.0
xunit.analyzers1.27.0
csharpier (tool)1.2.6
husky (tool)0.9.1

Net diff vs develop is only the six version bumps above. See #320 for the full change description.

Maintainer follow-ups (after merge)

  • Add CODEGEN_APP_CLIENT_ID / CODEGEN_APP_PRIVATE_KEY (GitHub App) to both Actions and Dependabot secret stores for the merge-bot.
  • Let Dependabot bring develop's deps up to match (or open a small sync PR).
  • Kick off the first publish via Actions → publish-release.yml → Run workflow once secrets are in.

🤖 Generated with Claude Code

dependabotBotand others added 30 commits August 19, 2025 20:51
Bumps csharpier from 1.1.1 to 1.1.2
Bumps xunit.analyzers from 1.23.0 to 1.24.0
Bumps xunit.runner.visualstudio from 3.1.3 to 3.1.4
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.1.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
- dependency-name: xunit.analyzers
dependency-version: 1.24.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
- dependency-name: xunit.runner.visualstudio
dependency-version: 3.1.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-0259308462
Bump the nuget-deps group with 3 updates
Bumps xunit.runner.visualstudio from 3.1.4 to 3.1.5
---
updated-dependencies:
- dependency-name: xunit.runner.visualstudio
dependency-version: 3.1.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…evelop/nuget-deps-6aadeae1b1
Bump the nuget-deps group with 1 update
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-39349b7924
Bump csharpier from 1.1.2 to 1.2.1
---
updated-dependencies:
- dependency-name: Serilog.Sinks.Console
dependency-version: 6.1.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…nuget-deps-602f419b37
Bump Serilog.Sinks.Console from 6.0.0 to 6.1.1
Bumps csharpier from 1.2.1 to 1.2.3
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-1689e99d0a
Bump the nuget-deps group with 1 update
Bumps the actions-deps group with 2 updates in the / directory: [actions/setup-dotnet](https://github.com/actions/setup-dotnet) and [actions/checkout](https://github.com/actions/checkout).
Updates `actions/setup-dotnet` from 4 to 5
- [Release notes](https://github.com/actions/setup-dotnet/releases)
- [Commits](actions/setup-dotnet@v4...v5)
Updates `actions/checkout` from 5 to 6
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v5...v6)
---
updated-dependencies:
- dependency-name: actions/setup-dotnet
dependency-version: '5'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
- dependency-name: actions/checkout
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps csharpier from 1.2.3 to 1.2.4
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-133b2bc611
Bump the nuget-deps group with 1 update
Bumps csharpier from 1.2.4 to 1.2.5
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-262ca43251
Bump the nuget-deps group with 1 update
* Initial plan
* Add using statement and simplify CallerMemberName attributes
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
* Initial plan
* Make HttpClient timeout configurable via TimeoutSeconds property
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Initial plan
* Replace redundant ToString() with string interpolation in FileExAsyncTests
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
* Initial plan
* Replace explicit ToString() calls with string interpolation
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
…304)
Bumps the actions-deps group with 1 update: [dependabot/fetch-metadata](https://github.com/dependabot/fetch-metadata).
Updates `dependabot/fetch-metadata` from 2 to 3
- [Release notes](https://github.com/dependabot/fetch-metadata/releases)
- [Commits](dependabot/fetch-metadata@v2...v3)
---
updated-dependencies:
- dependency-name: dependabot/fetch-metadata
dependency-version: '3'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
ptr727 added 2 commits June 4, 2026 18:28
* Convert to two-phase dual-publish release model
Replace publish-on-push with the ProjectTemplate/LanguageTags two-phase
model: PRs smoke-test only, and publish-release.yml publishes both branches
on a weekly schedule (Mon 02:00 UTC) or manual dispatch, with idempotent
no-op republish. Adopt the reusable workflow set (get-version,
build-nugetlibrary, build-release, build-datebadge), a branch-aware
Dependabot merge-bot, Central Package Management, and an AGENTS.md tracking
the template. NuGet.org-only (drop GitHub Packages); no Docker/exe/PyPI/codegen.
Reconcile the template's strict analyzers (AnalysisMode All +
TreatWarningsAsErrors) with the brownfield library by relaxing specific
rules in .editorconfig and IL3058 via NoWarn, all documented.
* Normalize line endings to .editorconfig; fix husky hook
Convert the workflow YAML, dependabot.yml, and AGENTS.md (added LF) to CRLF
per .editorconfig, and make .husky/pre-commit LF + executable so its shebang
execs on Linux/WSL. Add an .editorconfig rule pinning the hook to LF.
* Quote "$GITHUB_OUTPUT" in date-badge task
Resolve the one-time old->new structural conflicts in develop's favour and
take the max dependency/tool versions so main's newer Dependabot bumps are
not regressed (SourceLink 10.0.201, Serilog 4.3.1, Microsoft.NET.Test.Sdk
18.4.0, xunit.analyzers 1.27.0, csharpier 1.2.6, husky 0.9.1).
CopilotAI review requested due to automatic review settings June 5, 2026 13:07

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR lands the repo’s two-phase dual-publish release model onto main, aligning CI/release automation, Dependabot automation, and build configuration with the template-based workflow structure while reconciling dependency/tool versions via Central Package Management.

Changes:

  • Introduces new GitHub Actions workflow set for PR testing (unit tests + gated smoke build) and scheduled/manual publishing for both main and develop, plus a GitHub App–token-based merge-bot for Dependabot.
  • Moves shared build settings and package versions into Directory.Build.props and Directory.Packages.props, updating projects to use central package versions and tightening analyzer configuration.
  • Updates repo docs/config (AGENTS.md, README badge, .editorconfig/.gitignore, Husky hook) to match the new workflow and build conventions.

Reviewed changes

Copilot reviewed 38 out of 40 changed files in this pull request and generated 3 comments.

Show a summary per file
FileDescription
UtilitiesTests/UtilitiesTests.csprojDrops per-project framework/analyzer/package versions in favor of centralized props/package management.
UtilitiesTests/UtilitiesTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/StringHistoryTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/StringCompressionTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/StringCompressionAsyncTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/FileExAsyncTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/ExtensionsTests.csAdjusts null-handling tests and cleans up usings (but see review comments re: nullable warnings-as-errors).
UtilitiesTests/DownloadTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/DownloadAsyncTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/ConsoleTests.csRemoves now-redundant using directives under implicit usings.
Utilities/Utilities.csprojCentralizes core properties; adds IL3058 suppression for AOT-related warning and ensures packability.
Utilities/StringHistory.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/StringCompression.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/Format.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/FileExOptions.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/FileEx.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/Extensions.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/Download.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/ConsoleEx.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/CommandLineEx.csRemoves explicit usings now covered by implicit/global configuration.
Utilities.slnxAdds new solution items and updates workflow file references to the new model.
Sandbox/Sandbox.csprojCentralizes properties; adds IL3058 suppression and uses centrally managed package versions.
Sandbox/Program.csMinor cleanup (uses AppContext.BaseDirectory) and removes redundant using.
README.mdUpdates workflow badge to point at the new publishing workflow file.
Directory.Packages.propsIntroduces Central Package Management versions for dependencies/tools used across projects.
Directory.Build.propsIntroduces shared build properties (TFM, analyzers, warnings-as-errors, artifacts path, CPM enablement).
AGENTS.mdDocuments the new branching/release/workflow conventions and automation expectations.
.husky/pre-commitNormalizes formatting while keeping Husky hook behavior the same.
.gitignoreIgnores .artifacts directory used by the new shared build configuration.
.github/workflows/test-pull-request.ymlAdds PR workflow: unit tests + gated smoke build + required status aggregator job.
.github/workflows/publish-release.ymlAdds scheduled/manual (and optional push) publishing workflow with serialized concurrency and branch matrix.
.github/workflows/merge-bot-pull-request.ymlAdds Dependabot merge-bot using GitHub App token and branch-aware merge method.
.github/workflows/get-version-task.ymlAdds reusable NBGV version computation workflow for downstream build/publish tasks.
.github/workflows/DependabotAutoMerge.ymlRemoves legacy Dependabot auto-merge workflow.
.github/workflows/BuildPublishPipeline.ymlRemoves legacy build/publish pipeline workflow.
.github/workflows/build-release-task.ymlAdds reusable orchestrator workflow tying together versioning, build, NuGet push, and GitHub release creation.
.github/workflows/build-nugetlibrary-task.ymlAdds reusable workflow to build/package the library, optionally push to NuGet, and upload artifacts.
.github/workflows/build-datebadge-task.ymlAdds reusable workflow to generate/update a date badge (main-gated).
.github/dependabot.ymlReworks Dependabot config to target both main and develop across ecosystems.
.editorconfigAdds LF override for Husky hook file and documents analyzer severity relaxations for brownfield code.

Comment threadUtilitiesTests/ExtensionsTests.cs
Comment threadUtilitiesTests/ExtensionsTests.cs
Comment threadUtilitiesTests/ExtensionsTests.cs
@ptr727
ptr727 merged commit ed0d817 into mainJun 5, 2026
8 checks passed
@ptr727
ptr727 deleted the release/main branch June 5, 2026 13:13
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Release: two-phase dual-publish release model - #324

Merged
ptr727 merged 32 commits into
mainfrom
release/main
Jun 5, 2026
Merged

Release: two-phase dual-publish release model#324
ptr727 merged 32 commits into
mainfrom
release/main

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Summary

Land the two-phase dual-publish model on main, with fully signed & GitHub-verified history. This is main merged with develop (0f1616d), the one-time old→new structural conflicts resolved in develop's favour, and the max dependency/tool versions taken so main's newer Dependabot bumps are not regressed.

All introduced commits are committer = Pieter Viljoen <ptr727@users.noreply.github.com> and verified, satisfying required_signatures (supersedes #322/#323, which carried unverifiable web-flow-committed history).

Dependency reconciliation (max of develop/main)

Package / toolVersion
Microsoft.SourceLink.GitHub10.0.201
Serilog4.3.1
Microsoft.NET.Test.Sdk18.4.0
xunit.analyzers1.27.0
csharpier (tool)1.2.6
husky (tool)0.9.1

Net diff vs develop is only the six version bumps above. See #320 for the full change description.

Maintainer follow-ups (after merge)

  • Add CODEGEN_APP_CLIENT_ID / CODEGEN_APP_PRIVATE_KEY (GitHub App) to both Actions and Dependabot secret stores for the merge-bot.
  • Let Dependabot bring develop's deps up to match (or open a small sync PR).
  • Kick off the first publish via Actions → publish-release.yml → Run workflow once secrets are in.

🤖 Generated with Claude Code

dependabotBotand others added 30 commits August 19, 2025 20:51
Bumps csharpier from 1.1.1 to 1.1.2
Bumps xunit.analyzers from 1.23.0 to 1.24.0
Bumps xunit.runner.visualstudio from 3.1.3 to 3.1.4
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.1.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
- dependency-name: xunit.analyzers
dependency-version: 1.24.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
- dependency-name: xunit.runner.visualstudio
dependency-version: 3.1.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-0259308462
Bump the nuget-deps group with 3 updates
Bumps xunit.runner.visualstudio from 3.1.4 to 3.1.5
---
updated-dependencies:
- dependency-name: xunit.runner.visualstudio
dependency-version: 3.1.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…evelop/nuget-deps-6aadeae1b1
Bump the nuget-deps group with 1 update
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-39349b7924
Bump csharpier from 1.1.2 to 1.2.1
---
updated-dependencies:
- dependency-name: Serilog.Sinks.Console
dependency-version: 6.1.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…nuget-deps-602f419b37
Bump Serilog.Sinks.Console from 6.0.0 to 6.1.1
Bumps csharpier from 1.2.1 to 1.2.3
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-1689e99d0a
Bump the nuget-deps group with 1 update
Bumps the actions-deps group with 2 updates in the / directory: [actions/setup-dotnet](https://github.com/actions/setup-dotnet) and [actions/checkout](https://github.com/actions/checkout).
Updates `actions/setup-dotnet` from 4 to 5
- [Release notes](https://github.com/actions/setup-dotnet/releases)
- [Commits](actions/setup-dotnet@v4...v5)
Updates `actions/checkout` from 5 to 6
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v5...v6)
---
updated-dependencies:
- dependency-name: actions/setup-dotnet
dependency-version: '5'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
- dependency-name: actions/checkout
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps csharpier from 1.2.3 to 1.2.4
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-133b2bc611
Bump the nuget-deps group with 1 update
Bumps csharpier from 1.2.4 to 1.2.5
---
updated-dependencies:
- dependency-name: csharpier
dependency-version: 1.2.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: nuget-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
…op/nuget-deps-262ca43251
Bump the nuget-deps group with 1 update
* Initial plan
* Add using statement and simplify CallerMemberName attributes
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
* Initial plan
* Make HttpClient timeout configurable via TimeoutSeconds property
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Initial plan
* Replace redundant ToString() with string interpolation in FileExAsyncTests
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
* Initial plan
* Replace explicit ToString() calls with string interpolation
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: ptr727 <2061579+ptr727@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
…304)
Bumps the actions-deps group with 1 update: [dependabot/fetch-metadata](https://github.com/dependabot/fetch-metadata).
Updates `dependabot/fetch-metadata` from 2 to 3
- [Release notes](https://github.com/dependabot/fetch-metadata/releases)
- [Commits](dependabot/fetch-metadata@v2...v3)
---
updated-dependencies:
- dependency-name: dependabot/fetch-metadata
dependency-version: '3'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions-deps
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
ptr727 added 2 commits June 4, 2026 18:28
* Convert to two-phase dual-publish release model
Replace publish-on-push with the ProjectTemplate/LanguageTags two-phase
model: PRs smoke-test only, and publish-release.yml publishes both branches
on a weekly schedule (Mon 02:00 UTC) or manual dispatch, with idempotent
no-op republish. Adopt the reusable workflow set (get-version,
build-nugetlibrary, build-release, build-datebadge), a branch-aware
Dependabot merge-bot, Central Package Management, and an AGENTS.md tracking
the template. NuGet.org-only (drop GitHub Packages); no Docker/exe/PyPI/codegen.
Reconcile the template's strict analyzers (AnalysisMode All +
TreatWarningsAsErrors) with the brownfield library by relaxing specific
rules in .editorconfig and IL3058 via NoWarn, all documented.
* Normalize line endings to .editorconfig; fix husky hook
Convert the workflow YAML, dependabot.yml, and AGENTS.md (added LF) to CRLF
per .editorconfig, and make .husky/pre-commit LF + executable so its shebang
execs on Linux/WSL. Add an .editorconfig rule pinning the hook to LF.
* Quote "$GITHUB_OUTPUT" in date-badge task
Resolve the one-time old->new structural conflicts in develop's favour and
take the max dependency/tool versions so main's newer Dependabot bumps are
not regressed (SourceLink 10.0.201, Serilog 4.3.1, Microsoft.NET.Test.Sdk
18.4.0, xunit.analyzers 1.27.0, csharpier 1.2.6, husky 0.9.1).
CopilotAI review requested due to automatic review settings June 5, 2026 13:07

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR lands the repo’s two-phase dual-publish release model onto main, aligning CI/release automation, Dependabot automation, and build configuration with the template-based workflow structure while reconciling dependency/tool versions via Central Package Management.

Changes:

  • Introduces new GitHub Actions workflow set for PR testing (unit tests + gated smoke build) and scheduled/manual publishing for both main and develop, plus a GitHub App–token-based merge-bot for Dependabot.
  • Moves shared build settings and package versions into Directory.Build.props and Directory.Packages.props, updating projects to use central package versions and tightening analyzer configuration.
  • Updates repo docs/config (AGENTS.md, README badge, .editorconfig/.gitignore, Husky hook) to match the new workflow and build conventions.

Reviewed changes

Copilot reviewed 38 out of 40 changed files in this pull request and generated 3 comments.

Show a summary per file
FileDescription
UtilitiesTests/UtilitiesTests.csprojDrops per-project framework/analyzer/package versions in favor of centralized props/package management.
UtilitiesTests/UtilitiesTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/StringHistoryTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/StringCompressionTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/StringCompressionAsyncTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/FileExAsyncTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/ExtensionsTests.csAdjusts null-handling tests and cleans up usings (but see review comments re: nullable warnings-as-errors).
UtilitiesTests/DownloadTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/DownloadAsyncTests.csRemoves now-redundant using directives under implicit usings.
UtilitiesTests/ConsoleTests.csRemoves now-redundant using directives under implicit usings.
Utilities/Utilities.csprojCentralizes core properties; adds IL3058 suppression for AOT-related warning and ensures packability.
Utilities/StringHistory.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/StringCompression.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/Format.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/FileExOptions.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/FileEx.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/Extensions.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/Download.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/ConsoleEx.csRemoves explicit usings now covered by implicit/global configuration.
Utilities/CommandLineEx.csRemoves explicit usings now covered by implicit/global configuration.
Utilities.slnxAdds new solution items and updates workflow file references to the new model.
Sandbox/Sandbox.csprojCentralizes properties; adds IL3058 suppression and uses centrally managed package versions.
Sandbox/Program.csMinor cleanup (uses AppContext.BaseDirectory) and removes redundant using.
README.mdUpdates workflow badge to point at the new publishing workflow file.
Directory.Packages.propsIntroduces Central Package Management versions for dependencies/tools used across projects.
Directory.Build.propsIntroduces shared build properties (TFM, analyzers, warnings-as-errors, artifacts path, CPM enablement).
AGENTS.mdDocuments the new branching/release/workflow conventions and automation expectations.
.husky/pre-commitNormalizes formatting while keeping Husky hook behavior the same.
.gitignoreIgnores .artifacts directory used by the new shared build configuration.
.github/workflows/test-pull-request.ymlAdds PR workflow: unit tests + gated smoke build + required status aggregator job.
.github/workflows/publish-release.ymlAdds scheduled/manual (and optional push) publishing workflow with serialized concurrency and branch matrix.
.github/workflows/merge-bot-pull-request.ymlAdds Dependabot merge-bot using GitHub App token and branch-aware merge method.
.github/workflows/get-version-task.ymlAdds reusable NBGV version computation workflow for downstream build/publish tasks.
.github/workflows/DependabotAutoMerge.ymlRemoves legacy Dependabot auto-merge workflow.
.github/workflows/BuildPublishPipeline.ymlRemoves legacy build/publish pipeline workflow.
.github/workflows/build-release-task.ymlAdds reusable orchestrator workflow tying together versioning, build, NuGet push, and GitHub release creation.
.github/workflows/build-nugetlibrary-task.ymlAdds reusable workflow to build/package the library, optionally push to NuGet, and upload artifacts.
.github/workflows/build-datebadge-task.ymlAdds reusable workflow to generate/update a date badge (main-gated).
.github/dependabot.ymlReworks Dependabot config to target both main and develop across ecosystems.
.editorconfigAdds LF override for Husky hook file and documents analyzer severity relaxations for brownfield code.

Comment threadUtilitiesTests/ExtensionsTests.cs
Comment threadUtilitiesTests/ExtensionsTests.cs
Comment threadUtilitiesTests/ExtensionsTests.cs
@ptr727
ptr727 merged commit ed0d817 into mainJun 5, 2026
8 checks passed
@ptr727
ptr727 deleted the release/main branch June 5, 2026 13:13
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@ptr727