Promote develop to main: branch-scoped CI/CD + 3.6 - #350

Merged
ptr727 merged 4 commits into
mainfrom
develop
Jun 28, 2026
Merged

Promote develop to main: branch-scoped CI/CD + 3.6#350
ptr727 merged 4 commits into
mainfrom
develop

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Promote the branch-scoped self-publishing CI/CD migration to main, cutting the 3.6 stable release.

Carries the develop work: 5-workflow self-publishing pipeline (no codegen), WORKFLOW.md, repo-config/ (rulesets + settings as code), keyless OIDC NuGet publishing, flat Utilities.7z release packaging, reconciled docs, and the 3.6 version floor. The 3.6 prerelease published from develop verified clean (flat archive, NuGet package + symbols pushed).

Merge method is a merge commit (not squash) so main keeps a real reference to develop's commits.

🤖 Generated with Claude Code

dependabotBotand others added 4 commits June 23, 2026 14:55
Updated [Microsoft.NET.Test.Sdk](https://github.com/microsoft/vstest)
from 18.6.0 to 18.7.0.
<details>
<summary>Release notes</summary>
_Sourced from [Microsoft.NET.Test.Sdk's
releases](https://github.com/microsoft/vstest/releases)._
## 18.7.0
## What's Changed
* Add ARM64 msdia140.dll support to test platform packages by
@​jamesmcroft in microsoft/vstest#15689
* Update System.Memory from 4.5.5 to 4.6.3 by @​nohwnd in
microsoft/vstest#15706
## New Contributors
* @​jamesmcroft made their first contribution in
microsoft/vstest#15689
**Full Changelog**:
microsoft/vstest@v18.6.0...v18.7.0
Commits viewable in [compare
view](microsoft/vstest@v18.6.0...v18.7.0).
</details>
[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=Microsoft.NET.Test.Sdk&package-manager=nuget&previous-version=18.6.0&new-version=18.7.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…ce (#344)
Re-syncs this repo's carried governance/config artifacts and CI
orchestration to the current
[ptr727/ProjectTemplate](https://github.com/ptr727/ProjectTemplate)
(template-convergence barrier), and folds in this repo's task list. Held
for maintainer end-gate review - do not auto-merge.
## What this does
- **Carried artifacts re-synced to the template** (adapting only the
sanctioned placeholders): `AGENTS.md` "PR Review Etiquette",
`.github/copilot-instructions.md`, `.markdownlint-cli2.jsonc`,
`.editorconfig`, `.gitattributes`, and `CODESTYLE.md`. The carried files
are byte-for-byte the template's except for the documented adaptations
below. Carried workflow YAML stays CRLF to match the template's
checked-in form (per `.editorconfig`).
- **`CODESTYLE.md` carried whole** (General + .NET + Python). Only the
.NET section is consumed here; the Python section is inert but kept so
re-sync stays a wholesale replace.
- **Orchestration workflows aligned with the template:**
- `build-release-task.yml` / `build-nugetlibrary-task.yml`:
`github-release` decoupled from the build job; the download collects by
`pattern: release-asset-${{ inputs.branch }}-*` + `merge-multiple: true`
with `fail_on_unmatched_files: true`; the NuGet upload is renamed to
`release-asset-<branch>-nugetlibrary` and the unused `artifact-id`
output dropped; adds the main-only prerelease-suffix backstop.
- `merge-bot-pull-request.yml`: concurrency keyed per-PR
(`github.event.pull_request.number`) so bot PRs against the same base
queue independently.
- `publish-release.yml`: dispatch-from-default-branch guard.
- `test-pull-request.yml`: terminal `cleanup-artifacts` job (`needs:
[smoke-build]`), independent of `check-workflow-status` so housekeeping
never gates the required merge check.
## Documented adaptations (for review)
These are the only intentional deviations from the template; everything
else matches it. Sourced from `AGENTS.md` "Template Adaptations".
- **NuGet-only target set.** No Docker, executable, PyPI, or codegen
targets, so the corresponding `build-*-task.yml` / `run-codegen-*.yml`
workflows are absent and the merge-bot carries only the Dependabot path.
`publish-release.yml` keeps its repo-specific per-branch `date-badge`
matrix and omits the template's PyPI/Docker jobs.
- **Husky-driven clean-compile as the CI style gate.** The template
lints style directly in CI; this repo wires Husky.Net as a local
pre-commit gate and runs the same CSharpier + `dotnet format` checks in
CI via `dotnet husky run`, so the local gate and CI run identical
commands. Sanctioned by `CODESTYLE.md` "Clean-Compile Verification".
- **`.husky/pre-commit` LF pin.** `.editorconfig` adds a
`[.husky/pre-commit]` LF block and `.gitattributes` adds
`.husky/pre-commit text eol=lf` (the template's `[*.sh]` / `*.sh` rules
do not match the extensionless hook). Required because this repo ships
the Husky hook.
- **Brownfield analyzer relaxations.** A pre-existing set of analyzer
rules is relaxed to suggestion in `.editorconfig` (and `IL3058` via
`NoWarn`) to keep the published public API stable; each is documented
inline.
Validation: actionlint clean, markdownlint 0 errors, carried-config
diffs vs the template are EOL/adaptation-only.
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…up (#346)
Bumps the actions-deps group with 1 update:
[actions/setup-dotnet](https://github.com/actions/setup-dotnet).
Updates `actions/setup-dotnet` from 5.3.0 to 5.4.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/actions/setup-dotnet/releases">actions/setup-dotnet's
releases</a>.</em></p>
<blockquote>
<h2>v5.4.0</h2>
<h2>What's Changed</h2>
<h3>Enhancements</h3>
<ul>
<li>Improve global.json SDK version validation for rollForward by <a
href="https://github.com/priyagupta108"><code>@​priyagupta108</code></a>
in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/742">actions/setup-dotnet#742</a></li>
<li>Pin actions to commit SHAs in workflows by <a
href="https://github.com/priya-kinthali"><code>@​priya-kinthali</code></a>
in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/744">actions/setup-dotnet#744</a></li>
<li>Expand the CSC problem matcher to light up more errors on GitHub. by
<a
href="https://github.com/StephenCleary"><code>@​StephenCleary</code></a>
in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/717">actions/setup-dotnet#717</a></li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Docs(action): Explicitly mark all optional inputs with required:
false by <a
href="https://github.com/kranthipoturaju"><code>@​kranthipoturaju</code></a>
in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/737">actions/setup-dotnet#737</a></li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li>Fix global.json creation command by <a
href="https://github.com/michal2612"><code>@​michal2612</code></a> in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/694">actions/setup-dotnet#694</a></li>
</ul>
<h3>Dependency Updates</h3>
<ul>
<li>Upgrade <code>@​actions/cache</code> to 5.1.0, log cache write
denied by <a
href="https://github.com/jasongin"><code>@​jasongin</code></a> in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/746">actions/setup-dotnet#746</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/jasongin"><code>@​jasongin</code></a>
made their first contribution in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/746">actions/setup-dotnet#746</a></li>
<li><a
href="https://github.com/michal2612"><code>@​michal2612</code></a> made
their first contribution in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/694">actions/setup-dotnet#694</a></li>
<li><a
href="https://github.com/kranthipoturaju"><code>@​kranthipoturaju</code></a>
made their first contribution in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/737">actions/setup-dotnet#737</a></li>
<li><a
href="https://github.com/StephenCleary"><code>@​StephenCleary</code></a>
made their first contribution in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/717">actions/setup-dotnet#717</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/setup-dotnet/compare/v5...v5.4.0">https://github.com/actions/setup-dotnet/compare/v5...v5.4.0</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/actions/setup-dotnet/commit/26b0ec14cb23fa6904739307f278c14f94c95bf1"><code>26b0ec1</code></a>
Expand the CSC problem matcher to light up more errors on GitHub. (<a
href="https://redirect.github.com/actions/setup-dotnet/issues/717">#717</a>)</li>
<li><a
href="https://github.com/actions/setup-dotnet/commit/da5e5482f2d0700168cff080da45b50da8b60f0e"><code>da5e548</code></a>
docs(action): explicitly mark all optional inputs with required: false
(<a
href="https://redirect.github.com/actions/setup-dotnet/issues/737">#737</a>)</li>
<li><a
href="https://github.com/actions/setup-dotnet/commit/9bd3b44355ba7c500f3d2e029636c6d29ac5caab"><code>9bd3b44</code></a>
Improve readability of global.json creation command (<a
href="https://redirect.github.com/actions/setup-dotnet/issues/694">#694</a>)</li>
<li><a
href="https://github.com/actions/setup-dotnet/commit/4406a635cd2be9c92689ea22b2f74ea57297088c"><code>4406a63</code></a>
Bump <code>@​actions/cache</code> to 5.1.0, log cache write denied (<a
href="https://redirect.github.com/actions/setup-dotnet/issues/746">#746</a>)</li>
<li><a
href="https://github.com/actions/setup-dotnet/commit/dc3262dda80e97f1c7865b3b122e99240e30b738"><code>dc3262d</code></a>
pin actions to commit SHAs in workflows (<a
href="https://redirect.github.com/actions/setup-dotnet/issues/744">#744</a>)</li>
<li><a
href="https://github.com/actions/setup-dotnet/commit/95a3f8b067437dc9b2027a437f5dc3b4569ddd49"><code>95a3f8b</code></a>
Validate global.json SDK version before rollForward optimization (<a
href="https://redirect.github.com/actions/setup-dotnet/issues/742">#742</a>)</li>
<li>See full diff in <a
href="https://github.com/actions/setup-dotnet/compare/9a946fdbd5fb07b82b2f5a4466058b876ab72bb2...26b0ec14cb23fa6904739307f278c14f94c95bf1">compare
view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=actions/setup-dotnet&package-manager=github_actions&previous-version=5.3.0&new-version=5.4.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Ports the branch-scoped self-publishing CI/CD from
`ptr727/LanguageTags`, replacing the ProjectTemplate two-phase model.
`main` publishes stable releases and `develop` publishes prereleases;
each branch publishes itself when a shipped input changes. Utilities has
no codegen, so the generator workflows and merge-bot codegen job are
omitted.
## Workflows
- Remove `build-datebadge-task.yml`, `build-nugetlibrary-task.yml`,
`get-version-task.yml`.
- Add `validate-task.yml` (unit tests + CSharpier / `dotnet format
style` / markdownlint / cspell / actionlint).
- Rework `build-release-task.yml` (NBGV, keyless OIDC `NuGet/login`
push, flat `Utilities.7z` asset), `publish-release.yml` (push/dispatch
self-publisher with a shipped-input inclusion list),
`test-pull-request.yml` (validate + smoke-build + `Check pull request
workflow status job` aggregator), and `merge-bot-pull-request.yml`
(Dependabot auto-merge only).
## Config and docs
- Add `WORKFLOW.md` (canonical CI/CD spec, codegen sections removed) and
`repo-config/` (rulesets + settings as code, `delete_branch_on_merge`
off).
- Add `cspell.json` as the single spell-check source; reconcile
`AGENTS.md`, `CODESTYLE.md`, `.github/copilot-instructions.md`,
`.github/dependabot.yml`, `.vscode/tasks.json`, and `Utilities.slnx`.
- Bump version floor 3.5 -> 3.6; refresh `README.md` and `HISTORY.md`.
Verified locally: actionlint, markdownlint, cspell, YAML/JSON parse,
`bash -n configure.sh`, EOL per `.editorconfig`, and Husky
clean-compile.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 28, 2026 04:37

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Promotes the branch-scoped self-publishing CI/CD model (and related documentation/config-as-code) from develop to main, cutting the 3.6 stable release floor and aligning main with the new workflow contract.

Changes:

  • Introduce a reusable CI validation gate (validate-task.yml) and rework PR + publish workflows around branch-scoped, single-ref releases.
  • Add CI/CD specification and repo configuration-as-code (WORKFLOW.md, repo-config/) and refresh contributing/docs accordingly.
  • Bump the NBGV version floor to 3.6 and apply minor dependency/solution workspace updates.

Reviewed changes

Copilot reviewed 29 out of 29 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
WORKFLOW.mdAdds the canonical CI/CD workflow contract, architecture, and verification methodology.
version.jsonBumps NBGV version floor to 3.6 for the stable release line.
Utilities.slnxUpdates solution items/workflow references to match the new pipeline and docs.
Utilities.code-workspaceRemoves embedded CSpell dictionary in favor of a dedicated cspell.json.
repo-config/settings.jsonCodifies repo-level settings (merge methods, auto-merge, etc.).
repo-config/ruleset-main.jsonCodifies the main branch ruleset (merge-commit-only, required check, signatures).
repo-config/ruleset-develop.jsonCodifies the develop branch ruleset (squash-only/linear history, required check, signatures).
repo-config/README.mdDocuments how the configuration-as-code directory is applied and audited.
repo-config/configure.shAdds an idempotent gh api script to apply/check rulesets, settings, and required secrets.
README.mdUpdates distribution links, badges, and contributing guidance to reflect the new CI/CD model.
HISTORY.mdAdds v3.6 release notes describing the CI/CD and publishing changes.
Directory.Packages.propsUpdates Microsoft.NET.Test.Sdk to 18.7.0.
cspell.jsonAdds a repo-wide CSpell configuration and accepted word list.
CODESTYLE.mdUpdates code-style documentation to reflect current tooling and CI lint behavior.
AGENTS.mdRefactors agent guidance to point to WORKFLOW.md for CI/CD and clarifies review/merge gate expectations.
.vscode/tasks.jsonCleans up task file commentary and clarifies clean-compile vs convenience tasks.
.markdownlint-cli2.jsoncClarifies MD060 policy (table column style) in markdownlint configuration.
.github/workflows/validate-task.ymlAdds reusable validation workflow (unit tests + lint suite).
.github/workflows/test-pull-request.ymlSwitches PR gating to push-based CI for head-resolved workflow self-testing + required aggregator.
.github/workflows/publish-release.ymlReworks publishing to branch-scoped self-publishing on shipped-input changes or dispatch (no schedule).
.github/workflows/merge-bot-pull-request.ymlSimplifies merge-bot logic; enables auto-merge for Dependabot on both branches and disables on maintainer pushes.
.github/workflows/get-version-task.ymlRemoves standalone reusable version task (versioning now inlined into build-release-task).
.github/workflows/build-release-task.ymlConsolidates version/build/publish/release responsibilities; adds OIDC NuGet publishing and flat Utilities.7z asset.
.github/workflows/build-nugetlibrary-task.ymlRemoves legacy build task superseded by build-release-task.
.github/workflows/build-datebadge-task.ymlRemoves decorative date-badge workflow from the pipeline.
.github/dependabot.ymlTightens and shortens rationale comments while keeping dual-target updates.
.github/copilot-instructions.mdMinor wording updates in Copilot runbook and references.
.gitattributesClarifies EOL strategy and pins LF for execution-sensitive script classes.
.editorconfigRefines per-file-type EOL rules and adds ReSharper settings; adjusts C# analyzer settings.

Comment thread.editorconfig
Comment on lines 17 to 21
[*]
charset = utf-8
end_of_line = crlf
indent_size = 4
indent_style = space
insert_final_newline = true
Comment threadCODESTYLE.md
Comment on lines 198 to 202
1. **XML documentation**
- `<GenerateDocumentationFile>true</GenerateDocumentationFile>`
- Document all public surfaces.
- Missing XML comments for public APIs are suppressed (`.editorconfig`)
- Must document all public surfaces.
- Single-line summaries, additional details in remarks, document input parameters, return values, exceptions, and add crefs
@ptr727
ptr727 merged commit 1cbe6b2 into mainJun 28, 2026
17 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Promote develop to main: branch-scoped CI/CD + 3.6 - #350

Merged
ptr727 merged 4 commits into
mainfrom
develop
Jun 28, 2026
Merged

Promote develop to main: branch-scoped CI/CD + 3.6#350
ptr727 merged 4 commits into
mainfrom
develop

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Promote the branch-scoped self-publishing CI/CD migration to main, cutting the 3.6 stable release.

Carries the develop work: 5-workflow self-publishing pipeline (no codegen), WORKFLOW.md, repo-config/ (rulesets + settings as code), keyless OIDC NuGet publishing, flat Utilities.7z release packaging, reconciled docs, and the 3.6 version floor. The 3.6 prerelease published from develop verified clean (flat archive, NuGet package + symbols pushed).

Merge method is a merge commit (not squash) so main keeps a real reference to develop's commits.

🤖 Generated with Claude Code

dependabotBotand others added 4 commits June 23, 2026 14:55
Updated [Microsoft.NET.Test.Sdk](https://github.com/microsoft/vstest)
from 18.6.0 to 18.7.0.
<details>
<summary>Release notes</summary>
_Sourced from [Microsoft.NET.Test.Sdk's
releases](https://github.com/microsoft/vstest/releases)._
## 18.7.0
## What's Changed
* Add ARM64 msdia140.dll support to test platform packages by
@​jamesmcroft in microsoft/vstest#15689
* Update System.Memory from 4.5.5 to 4.6.3 by @​nohwnd in
microsoft/vstest#15706
## New Contributors
* @​jamesmcroft made their first contribution in
microsoft/vstest#15689
**Full Changelog**:
microsoft/vstest@v18.6.0...v18.7.0
Commits viewable in [compare
view](microsoft/vstest@v18.6.0...v18.7.0).
</details>
[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=Microsoft.NET.Test.Sdk&package-manager=nuget&previous-version=18.6.0&new-version=18.7.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…ce (#344)
Re-syncs this repo's carried governance/config artifacts and CI
orchestration to the current
[ptr727/ProjectTemplate](https://github.com/ptr727/ProjectTemplate)
(template-convergence barrier), and folds in this repo's task list. Held
for maintainer end-gate review - do not auto-merge.
## What this does
- **Carried artifacts re-synced to the template** (adapting only the
sanctioned placeholders): `AGENTS.md` "PR Review Etiquette",
`.github/copilot-instructions.md`, `.markdownlint-cli2.jsonc`,
`.editorconfig`, `.gitattributes`, and `CODESTYLE.md`. The carried files
are byte-for-byte the template's except for the documented adaptations
below. Carried workflow YAML stays CRLF to match the template's
checked-in form (per `.editorconfig`).
- **`CODESTYLE.md` carried whole** (General + .NET + Python). Only the
.NET section is consumed here; the Python section is inert but kept so
re-sync stays a wholesale replace.
- **Orchestration workflows aligned with the template:**
- `build-release-task.yml` / `build-nugetlibrary-task.yml`:
`github-release` decoupled from the build job; the download collects by
`pattern: release-asset-${{ inputs.branch }}-*` + `merge-multiple: true`
with `fail_on_unmatched_files: true`; the NuGet upload is renamed to
`release-asset-<branch>-nugetlibrary` and the unused `artifact-id`
output dropped; adds the main-only prerelease-suffix backstop.
- `merge-bot-pull-request.yml`: concurrency keyed per-PR
(`github.event.pull_request.number`) so bot PRs against the same base
queue independently.
- `publish-release.yml`: dispatch-from-default-branch guard.
- `test-pull-request.yml`: terminal `cleanup-artifacts` job (`needs:
[smoke-build]`), independent of `check-workflow-status` so housekeeping
never gates the required merge check.
## Documented adaptations (for review)
These are the only intentional deviations from the template; everything
else matches it. Sourced from `AGENTS.md` "Template Adaptations".
- **NuGet-only target set.** No Docker, executable, PyPI, or codegen
targets, so the corresponding `build-*-task.yml` / `run-codegen-*.yml`
workflows are absent and the merge-bot carries only the Dependabot path.
`publish-release.yml` keeps its repo-specific per-branch `date-badge`
matrix and omits the template's PyPI/Docker jobs.
- **Husky-driven clean-compile as the CI style gate.** The template
lints style directly in CI; this repo wires Husky.Net as a local
pre-commit gate and runs the same CSharpier + `dotnet format` checks in
CI via `dotnet husky run`, so the local gate and CI run identical
commands. Sanctioned by `CODESTYLE.md` "Clean-Compile Verification".
- **`.husky/pre-commit` LF pin.** `.editorconfig` adds a
`[.husky/pre-commit]` LF block and `.gitattributes` adds
`.husky/pre-commit text eol=lf` (the template's `[*.sh]` / `*.sh` rules
do not match the extensionless hook). Required because this repo ships
the Husky hook.
- **Brownfield analyzer relaxations.** A pre-existing set of analyzer
rules is relaxed to suggestion in `.editorconfig` (and `IL3058` via
`NoWarn`) to keep the published public API stable; each is documented
inline.
Validation: actionlint clean, markdownlint 0 errors, carried-config
diffs vs the template are EOL/adaptation-only.
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…up (#346)
Bumps the actions-deps group with 1 update:
[actions/setup-dotnet](https://github.com/actions/setup-dotnet).
Updates `actions/setup-dotnet` from 5.3.0 to 5.4.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/actions/setup-dotnet/releases">actions/setup-dotnet's
releases</a>.</em></p>
<blockquote>
<h2>v5.4.0</h2>
<h2>What's Changed</h2>
<h3>Enhancements</h3>
<ul>
<li>Improve global.json SDK version validation for rollForward by <a
href="https://github.com/priyagupta108"><code>@​priyagupta108</code></a>
in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/742">actions/setup-dotnet#742</a></li>
<li>Pin actions to commit SHAs in workflows by <a
href="https://github.com/priya-kinthali"><code>@​priya-kinthali</code></a>
in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/744">actions/setup-dotnet#744</a></li>
<li>Expand the CSC problem matcher to light up more errors on GitHub. by
<a
href="https://github.com/StephenCleary"><code>@​StephenCleary</code></a>
in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/717">actions/setup-dotnet#717</a></li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Docs(action): Explicitly mark all optional inputs with required:
false by <a
href="https://github.com/kranthipoturaju"><code>@​kranthipoturaju</code></a>
in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/737">actions/setup-dotnet#737</a></li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li>Fix global.json creation command by <a
href="https://github.com/michal2612"><code>@​michal2612</code></a> in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/694">actions/setup-dotnet#694</a></li>
</ul>
<h3>Dependency Updates</h3>
<ul>
<li>Upgrade <code>@​actions/cache</code> to 5.1.0, log cache write
denied by <a
href="https://github.com/jasongin"><code>@​jasongin</code></a> in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/746">actions/setup-dotnet#746</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/jasongin"><code>@​jasongin</code></a>
made their first contribution in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/746">actions/setup-dotnet#746</a></li>
<li><a
href="https://github.com/michal2612"><code>@​michal2612</code></a> made
their first contribution in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/694">actions/setup-dotnet#694</a></li>
<li><a
href="https://github.com/kranthipoturaju"><code>@​kranthipoturaju</code></a>
made their first contribution in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/737">actions/setup-dotnet#737</a></li>
<li><a
href="https://github.com/StephenCleary"><code>@​StephenCleary</code></a>
made their first contribution in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/717">actions/setup-dotnet#717</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/setup-dotnet/compare/v5...v5.4.0">https://github.com/actions/setup-dotnet/compare/v5...v5.4.0</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/actions/setup-dotnet/commit/26b0ec14cb23fa6904739307f278c14f94c95bf1"><code>26b0ec1</code></a>
Expand the CSC problem matcher to light up more errors on GitHub. (<a
href="https://redirect.github.com/actions/setup-dotnet/issues/717">#717</a>)</li>
<li><a
href="https://github.com/actions/setup-dotnet/commit/da5e5482f2d0700168cff080da45b50da8b60f0e"><code>da5e548</code></a>
docs(action): explicitly mark all optional inputs with required: false
(<a
href="https://redirect.github.com/actions/setup-dotnet/issues/737">#737</a>)</li>
<li><a
href="https://github.com/actions/setup-dotnet/commit/9bd3b44355ba7c500f3d2e029636c6d29ac5caab"><code>9bd3b44</code></a>
Improve readability of global.json creation command (<a
href="https://redirect.github.com/actions/setup-dotnet/issues/694">#694</a>)</li>
<li><a
href="https://github.com/actions/setup-dotnet/commit/4406a635cd2be9c92689ea22b2f74ea57297088c"><code>4406a63</code></a>
Bump <code>@​actions/cache</code> to 5.1.0, log cache write denied (<a
href="https://redirect.github.com/actions/setup-dotnet/issues/746">#746</a>)</li>
<li><a
href="https://github.com/actions/setup-dotnet/commit/dc3262dda80e97f1c7865b3b122e99240e30b738"><code>dc3262d</code></a>
pin actions to commit SHAs in workflows (<a
href="https://redirect.github.com/actions/setup-dotnet/issues/744">#744</a>)</li>
<li><a
href="https://github.com/actions/setup-dotnet/commit/95a3f8b067437dc9b2027a437f5dc3b4569ddd49"><code>95a3f8b</code></a>
Validate global.json SDK version before rollForward optimization (<a
href="https://redirect.github.com/actions/setup-dotnet/issues/742">#742</a>)</li>
<li>See full diff in <a
href="https://github.com/actions/setup-dotnet/compare/9a946fdbd5fb07b82b2f5a4466058b876ab72bb2...26b0ec14cb23fa6904739307f278c14f94c95bf1">compare
view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=actions/setup-dotnet&package-manager=github_actions&previous-version=5.3.0&new-version=5.4.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Ports the branch-scoped self-publishing CI/CD from
`ptr727/LanguageTags`, replacing the ProjectTemplate two-phase model.
`main` publishes stable releases and `develop` publishes prereleases;
each branch publishes itself when a shipped input changes. Utilities has
no codegen, so the generator workflows and merge-bot codegen job are
omitted.
## Workflows
- Remove `build-datebadge-task.yml`, `build-nugetlibrary-task.yml`,
`get-version-task.yml`.
- Add `validate-task.yml` (unit tests + CSharpier / `dotnet format
style` / markdownlint / cspell / actionlint).
- Rework `build-release-task.yml` (NBGV, keyless OIDC `NuGet/login`
push, flat `Utilities.7z` asset), `publish-release.yml` (push/dispatch
self-publisher with a shipped-input inclusion list),
`test-pull-request.yml` (validate + smoke-build + `Check pull request
workflow status job` aggregator), and `merge-bot-pull-request.yml`
(Dependabot auto-merge only).
## Config and docs
- Add `WORKFLOW.md` (canonical CI/CD spec, codegen sections removed) and
`repo-config/` (rulesets + settings as code, `delete_branch_on_merge`
off).
- Add `cspell.json` as the single spell-check source; reconcile
`AGENTS.md`, `CODESTYLE.md`, `.github/copilot-instructions.md`,
`.github/dependabot.yml`, `.vscode/tasks.json`, and `Utilities.slnx`.
- Bump version floor 3.5 -> 3.6; refresh `README.md` and `HISTORY.md`.
Verified locally: actionlint, markdownlint, cspell, YAML/JSON parse,
`bash -n configure.sh`, EOL per `.editorconfig`, and Husky
clean-compile.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 28, 2026 04:37

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Promotes the branch-scoped self-publishing CI/CD model (and related documentation/config-as-code) from develop to main, cutting the 3.6 stable release floor and aligning main with the new workflow contract.

Changes:

  • Introduce a reusable CI validation gate (validate-task.yml) and rework PR + publish workflows around branch-scoped, single-ref releases.
  • Add CI/CD specification and repo configuration-as-code (WORKFLOW.md, repo-config/) and refresh contributing/docs accordingly.
  • Bump the NBGV version floor to 3.6 and apply minor dependency/solution workspace updates.

Reviewed changes

Copilot reviewed 29 out of 29 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
WORKFLOW.mdAdds the canonical CI/CD workflow contract, architecture, and verification methodology.
version.jsonBumps NBGV version floor to 3.6 for the stable release line.
Utilities.slnxUpdates solution items/workflow references to match the new pipeline and docs.
Utilities.code-workspaceRemoves embedded CSpell dictionary in favor of a dedicated cspell.json.
repo-config/settings.jsonCodifies repo-level settings (merge methods, auto-merge, etc.).
repo-config/ruleset-main.jsonCodifies the main branch ruleset (merge-commit-only, required check, signatures).
repo-config/ruleset-develop.jsonCodifies the develop branch ruleset (squash-only/linear history, required check, signatures).
repo-config/README.mdDocuments how the configuration-as-code directory is applied and audited.
repo-config/configure.shAdds an idempotent gh api script to apply/check rulesets, settings, and required secrets.
README.mdUpdates distribution links, badges, and contributing guidance to reflect the new CI/CD model.
HISTORY.mdAdds v3.6 release notes describing the CI/CD and publishing changes.
Directory.Packages.propsUpdates Microsoft.NET.Test.Sdk to 18.7.0.
cspell.jsonAdds a repo-wide CSpell configuration and accepted word list.
CODESTYLE.mdUpdates code-style documentation to reflect current tooling and CI lint behavior.
AGENTS.mdRefactors agent guidance to point to WORKFLOW.md for CI/CD and clarifies review/merge gate expectations.
.vscode/tasks.jsonCleans up task file commentary and clarifies clean-compile vs convenience tasks.
.markdownlint-cli2.jsoncClarifies MD060 policy (table column style) in markdownlint configuration.
.github/workflows/validate-task.ymlAdds reusable validation workflow (unit tests + lint suite).
.github/workflows/test-pull-request.ymlSwitches PR gating to push-based CI for head-resolved workflow self-testing + required aggregator.
.github/workflows/publish-release.ymlReworks publishing to branch-scoped self-publishing on shipped-input changes or dispatch (no schedule).
.github/workflows/merge-bot-pull-request.ymlSimplifies merge-bot logic; enables auto-merge for Dependabot on both branches and disables on maintainer pushes.
.github/workflows/get-version-task.ymlRemoves standalone reusable version task (versioning now inlined into build-release-task).
.github/workflows/build-release-task.ymlConsolidates version/build/publish/release responsibilities; adds OIDC NuGet publishing and flat Utilities.7z asset.
.github/workflows/build-nugetlibrary-task.ymlRemoves legacy build task superseded by build-release-task.
.github/workflows/build-datebadge-task.ymlRemoves decorative date-badge workflow from the pipeline.
.github/dependabot.ymlTightens and shortens rationale comments while keeping dual-target updates.
.github/copilot-instructions.mdMinor wording updates in Copilot runbook and references.
.gitattributesClarifies EOL strategy and pins LF for execution-sensitive script classes.
.editorconfigRefines per-file-type EOL rules and adds ReSharper settings; adjusts C# analyzer settings.

Comment thread.editorconfig
Comment on lines 17 to 21
[*]
charset = utf-8
end_of_line = crlf
indent_size = 4
indent_style = space
insert_final_newline = true
Comment threadCODESTYLE.md
Comment on lines 198 to 202
1. **XML documentation**
- `<GenerateDocumentationFile>true</GenerateDocumentationFile>`
- Document all public surfaces.
- Missing XML comments for public APIs are suppressed (`.editorconfig`)
- Must document all public surfaces.
- Single-line summaries, additional details in remarks, document input parameters, return values, exceptions, and add crefs
@ptr727
ptr727 merged commit 1cbe6b2 into mainJun 28, 2026
17 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Promote develop to main: branch-scoped CI/CD + 3.6 - #350

Merged
ptr727 merged 4 commits into
mainfrom
develop
Jun 28, 2026
Merged

Promote develop to main: branch-scoped CI/CD + 3.6#350
ptr727 merged 4 commits into
mainfrom
develop

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Promote the branch-scoped self-publishing CI/CD migration to main, cutting the 3.6 stable release.

Carries the develop work: 5-workflow self-publishing pipeline (no codegen), WORKFLOW.md, repo-config/ (rulesets + settings as code), keyless OIDC NuGet publishing, flat Utilities.7z release packaging, reconciled docs, and the 3.6 version floor. The 3.6 prerelease published from develop verified clean (flat archive, NuGet package + symbols pushed).

Merge method is a merge commit (not squash) so main keeps a real reference to develop's commits.

🤖 Generated with Claude Code

dependabotBotand others added 4 commits June 23, 2026 14:55
Updated [Microsoft.NET.Test.Sdk](https://github.com/microsoft/vstest)
from 18.6.0 to 18.7.0.
<details>
<summary>Release notes</summary>
_Sourced from [Microsoft.NET.Test.Sdk's
releases](https://github.com/microsoft/vstest/releases)._
## 18.7.0
## What's Changed
* Add ARM64 msdia140.dll support to test platform packages by
@​jamesmcroft in microsoft/vstest#15689
* Update System.Memory from 4.5.5 to 4.6.3 by @​nohwnd in
microsoft/vstest#15706
## New Contributors
* @​jamesmcroft made their first contribution in
microsoft/vstest#15689
**Full Changelog**:
microsoft/vstest@v18.6.0...v18.7.0
Commits viewable in [compare
view](microsoft/vstest@v18.6.0...v18.7.0).
</details>
[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=Microsoft.NET.Test.Sdk&package-manager=nuget&previous-version=18.6.0&new-version=18.7.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…ce (#344)
Re-syncs this repo's carried governance/config artifacts and CI
orchestration to the current
[ptr727/ProjectTemplate](https://github.com/ptr727/ProjectTemplate)
(template-convergence barrier), and folds in this repo's task list. Held
for maintainer end-gate review - do not auto-merge.
## What this does
- **Carried artifacts re-synced to the template** (adapting only the
sanctioned placeholders): `AGENTS.md` "PR Review Etiquette",
`.github/copilot-instructions.md`, `.markdownlint-cli2.jsonc`,
`.editorconfig`, `.gitattributes`, and `CODESTYLE.md`. The carried files
are byte-for-byte the template's except for the documented adaptations
below. Carried workflow YAML stays CRLF to match the template's
checked-in form (per `.editorconfig`).
- **`CODESTYLE.md` carried whole** (General + .NET + Python). Only the
.NET section is consumed here; the Python section is inert but kept so
re-sync stays a wholesale replace.
- **Orchestration workflows aligned with the template:**
- `build-release-task.yml` / `build-nugetlibrary-task.yml`:
`github-release` decoupled from the build job; the download collects by
`pattern: release-asset-${{ inputs.branch }}-*` + `merge-multiple: true`
with `fail_on_unmatched_files: true`; the NuGet upload is renamed to
`release-asset-<branch>-nugetlibrary` and the unused `artifact-id`
output dropped; adds the main-only prerelease-suffix backstop.
- `merge-bot-pull-request.yml`: concurrency keyed per-PR
(`github.event.pull_request.number`) so bot PRs against the same base
queue independently.
- `publish-release.yml`: dispatch-from-default-branch guard.
- `test-pull-request.yml`: terminal `cleanup-artifacts` job (`needs:
[smoke-build]`), independent of `check-workflow-status` so housekeeping
never gates the required merge check.
## Documented adaptations (for review)
These are the only intentional deviations from the template; everything
else matches it. Sourced from `AGENTS.md` "Template Adaptations".
- **NuGet-only target set.** No Docker, executable, PyPI, or codegen
targets, so the corresponding `build-*-task.yml` / `run-codegen-*.yml`
workflows are absent and the merge-bot carries only the Dependabot path.
`publish-release.yml` keeps its repo-specific per-branch `date-badge`
matrix and omits the template's PyPI/Docker jobs.
- **Husky-driven clean-compile as the CI style gate.** The template
lints style directly in CI; this repo wires Husky.Net as a local
pre-commit gate and runs the same CSharpier + `dotnet format` checks in
CI via `dotnet husky run`, so the local gate and CI run identical
commands. Sanctioned by `CODESTYLE.md` "Clean-Compile Verification".
- **`.husky/pre-commit` LF pin.** `.editorconfig` adds a
`[.husky/pre-commit]` LF block and `.gitattributes` adds
`.husky/pre-commit text eol=lf` (the template's `[*.sh]` / `*.sh` rules
do not match the extensionless hook). Required because this repo ships
the Husky hook.
- **Brownfield analyzer relaxations.** A pre-existing set of analyzer
rules is relaxed to suggestion in `.editorconfig` (and `IL3058` via
`NoWarn`) to keep the published public API stable; each is documented
inline.
Validation: actionlint clean, markdownlint 0 errors, carried-config
diffs vs the template are EOL/adaptation-only.
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…up (#346)
Bumps the actions-deps group with 1 update:
[actions/setup-dotnet](https://github.com/actions/setup-dotnet).
Updates `actions/setup-dotnet` from 5.3.0 to 5.4.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/actions/setup-dotnet/releases">actions/setup-dotnet's
releases</a>.</em></p>
<blockquote>
<h2>v5.4.0</h2>
<h2>What's Changed</h2>
<h3>Enhancements</h3>
<ul>
<li>Improve global.json SDK version validation for rollForward by <a
href="https://github.com/priyagupta108"><code>@​priyagupta108</code></a>
in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/742">actions/setup-dotnet#742</a></li>
<li>Pin actions to commit SHAs in workflows by <a
href="https://github.com/priya-kinthali"><code>@​priya-kinthali</code></a>
in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/744">actions/setup-dotnet#744</a></li>
<li>Expand the CSC problem matcher to light up more errors on GitHub. by
<a
href="https://github.com/StephenCleary"><code>@​StephenCleary</code></a>
in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/717">actions/setup-dotnet#717</a></li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Docs(action): Explicitly mark all optional inputs with required:
false by <a
href="https://github.com/kranthipoturaju"><code>@​kranthipoturaju</code></a>
in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/737">actions/setup-dotnet#737</a></li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li>Fix global.json creation command by <a
href="https://github.com/michal2612"><code>@​michal2612</code></a> in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/694">actions/setup-dotnet#694</a></li>
</ul>
<h3>Dependency Updates</h3>
<ul>
<li>Upgrade <code>@​actions/cache</code> to 5.1.0, log cache write
denied by <a
href="https://github.com/jasongin"><code>@​jasongin</code></a> in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/746">actions/setup-dotnet#746</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/jasongin"><code>@​jasongin</code></a>
made their first contribution in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/746">actions/setup-dotnet#746</a></li>
<li><a
href="https://github.com/michal2612"><code>@​michal2612</code></a> made
their first contribution in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/694">actions/setup-dotnet#694</a></li>
<li><a
href="https://github.com/kranthipoturaju"><code>@​kranthipoturaju</code></a>
made their first contribution in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/737">actions/setup-dotnet#737</a></li>
<li><a
href="https://github.com/StephenCleary"><code>@​StephenCleary</code></a>
made their first contribution in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/717">actions/setup-dotnet#717</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/setup-dotnet/compare/v5...v5.4.0">https://github.com/actions/setup-dotnet/compare/v5...v5.4.0</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/actions/setup-dotnet/commit/26b0ec14cb23fa6904739307f278c14f94c95bf1"><code>26b0ec1</code></a>
Expand the CSC problem matcher to light up more errors on GitHub. (<a
href="https://redirect.github.com/actions/setup-dotnet/issues/717">#717</a>)</li>
<li><a
href="https://github.com/actions/setup-dotnet/commit/da5e5482f2d0700168cff080da45b50da8b60f0e"><code>da5e548</code></a>
docs(action): explicitly mark all optional inputs with required: false
(<a
href="https://redirect.github.com/actions/setup-dotnet/issues/737">#737</a>)</li>
<li><a
href="https://github.com/actions/setup-dotnet/commit/9bd3b44355ba7c500f3d2e029636c6d29ac5caab"><code>9bd3b44</code></a>
Improve readability of global.json creation command (<a
href="https://redirect.github.com/actions/setup-dotnet/issues/694">#694</a>)</li>
<li><a
href="https://github.com/actions/setup-dotnet/commit/4406a635cd2be9c92689ea22b2f74ea57297088c"><code>4406a63</code></a>
Bump <code>@​actions/cache</code> to 5.1.0, log cache write denied (<a
href="https://redirect.github.com/actions/setup-dotnet/issues/746">#746</a>)</li>
<li><a
href="https://github.com/actions/setup-dotnet/commit/dc3262dda80e97f1c7865b3b122e99240e30b738"><code>dc3262d</code></a>
pin actions to commit SHAs in workflows (<a
href="https://redirect.github.com/actions/setup-dotnet/issues/744">#744</a>)</li>
<li><a
href="https://github.com/actions/setup-dotnet/commit/95a3f8b067437dc9b2027a437f5dc3b4569ddd49"><code>95a3f8b</code></a>
Validate global.json SDK version before rollForward optimization (<a
href="https://redirect.github.com/actions/setup-dotnet/issues/742">#742</a>)</li>
<li>See full diff in <a
href="https://github.com/actions/setup-dotnet/compare/9a946fdbd5fb07b82b2f5a4466058b876ab72bb2...26b0ec14cb23fa6904739307f278c14f94c95bf1">compare
view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=actions/setup-dotnet&package-manager=github_actions&previous-version=5.3.0&new-version=5.4.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Ports the branch-scoped self-publishing CI/CD from
`ptr727/LanguageTags`, replacing the ProjectTemplate two-phase model.
`main` publishes stable releases and `develop` publishes prereleases;
each branch publishes itself when a shipped input changes. Utilities has
no codegen, so the generator workflows and merge-bot codegen job are
omitted.
## Workflows
- Remove `build-datebadge-task.yml`, `build-nugetlibrary-task.yml`,
`get-version-task.yml`.
- Add `validate-task.yml` (unit tests + CSharpier / `dotnet format
style` / markdownlint / cspell / actionlint).
- Rework `build-release-task.yml` (NBGV, keyless OIDC `NuGet/login`
push, flat `Utilities.7z` asset), `publish-release.yml` (push/dispatch
self-publisher with a shipped-input inclusion list),
`test-pull-request.yml` (validate + smoke-build + `Check pull request
workflow status job` aggregator), and `merge-bot-pull-request.yml`
(Dependabot auto-merge only).
## Config and docs
- Add `WORKFLOW.md` (canonical CI/CD spec, codegen sections removed) and
`repo-config/` (rulesets + settings as code, `delete_branch_on_merge`
off).
- Add `cspell.json` as the single spell-check source; reconcile
`AGENTS.md`, `CODESTYLE.md`, `.github/copilot-instructions.md`,
`.github/dependabot.yml`, `.vscode/tasks.json`, and `Utilities.slnx`.
- Bump version floor 3.5 -> 3.6; refresh `README.md` and `HISTORY.md`.
Verified locally: actionlint, markdownlint, cspell, YAML/JSON parse,
`bash -n configure.sh`, EOL per `.editorconfig`, and Husky
clean-compile.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 28, 2026 04:37

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Promotes the branch-scoped self-publishing CI/CD model (and related documentation/config-as-code) from develop to main, cutting the 3.6 stable release floor and aligning main with the new workflow contract.

Changes:

  • Introduce a reusable CI validation gate (validate-task.yml) and rework PR + publish workflows around branch-scoped, single-ref releases.
  • Add CI/CD specification and repo configuration-as-code (WORKFLOW.md, repo-config/) and refresh contributing/docs accordingly.
  • Bump the NBGV version floor to 3.6 and apply minor dependency/solution workspace updates.

Reviewed changes

Copilot reviewed 29 out of 29 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
WORKFLOW.mdAdds the canonical CI/CD workflow contract, architecture, and verification methodology.
version.jsonBumps NBGV version floor to 3.6 for the stable release line.
Utilities.slnxUpdates solution items/workflow references to match the new pipeline and docs.
Utilities.code-workspaceRemoves embedded CSpell dictionary in favor of a dedicated cspell.json.
repo-config/settings.jsonCodifies repo-level settings (merge methods, auto-merge, etc.).
repo-config/ruleset-main.jsonCodifies the main branch ruleset (merge-commit-only, required check, signatures).
repo-config/ruleset-develop.jsonCodifies the develop branch ruleset (squash-only/linear history, required check, signatures).
repo-config/README.mdDocuments how the configuration-as-code directory is applied and audited.
repo-config/configure.shAdds an idempotent gh api script to apply/check rulesets, settings, and required secrets.
README.mdUpdates distribution links, badges, and contributing guidance to reflect the new CI/CD model.
HISTORY.mdAdds v3.6 release notes describing the CI/CD and publishing changes.
Directory.Packages.propsUpdates Microsoft.NET.Test.Sdk to 18.7.0.
cspell.jsonAdds a repo-wide CSpell configuration and accepted word list.
CODESTYLE.mdUpdates code-style documentation to reflect current tooling and CI lint behavior.
AGENTS.mdRefactors agent guidance to point to WORKFLOW.md for CI/CD and clarifies review/merge gate expectations.
.vscode/tasks.jsonCleans up task file commentary and clarifies clean-compile vs convenience tasks.
.markdownlint-cli2.jsoncClarifies MD060 policy (table column style) in markdownlint configuration.
.github/workflows/validate-task.ymlAdds reusable validation workflow (unit tests + lint suite).
.github/workflows/test-pull-request.ymlSwitches PR gating to push-based CI for head-resolved workflow self-testing + required aggregator.
.github/workflows/publish-release.ymlReworks publishing to branch-scoped self-publishing on shipped-input changes or dispatch (no schedule).
.github/workflows/merge-bot-pull-request.ymlSimplifies merge-bot logic; enables auto-merge for Dependabot on both branches and disables on maintainer pushes.
.github/workflows/get-version-task.ymlRemoves standalone reusable version task (versioning now inlined into build-release-task).
.github/workflows/build-release-task.ymlConsolidates version/build/publish/release responsibilities; adds OIDC NuGet publishing and flat Utilities.7z asset.
.github/workflows/build-nugetlibrary-task.ymlRemoves legacy build task superseded by build-release-task.
.github/workflows/build-datebadge-task.ymlRemoves decorative date-badge workflow from the pipeline.
.github/dependabot.ymlTightens and shortens rationale comments while keeping dual-target updates.
.github/copilot-instructions.mdMinor wording updates in Copilot runbook and references.
.gitattributesClarifies EOL strategy and pins LF for execution-sensitive script classes.
.editorconfigRefines per-file-type EOL rules and adds ReSharper settings; adjusts C# analyzer settings.

Comment thread.editorconfig
Comment on lines 17 to 21
[*]
charset = utf-8
end_of_line = crlf
indent_size = 4
indent_style = space
insert_final_newline = true
Comment threadCODESTYLE.md
Comment on lines 198 to 202
1. **XML documentation**
- `<GenerateDocumentationFile>true</GenerateDocumentationFile>`
- Document all public surfaces.
- Missing XML comments for public APIs are suppressed (`.editorconfig`)
- Must document all public surfaces.
- Single-line summaries, additional details in remarks, document input parameters, return values, exceptions, and add crefs
@ptr727
ptr727 merged commit 1cbe6b2 into mainJun 28, 2026
17 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Promote develop to main: branch-scoped CI/CD + 3.6 - #350

Merged
ptr727 merged 4 commits into
mainfrom
develop
Jun 28, 2026
Merged

Promote develop to main: branch-scoped CI/CD + 3.6#350
ptr727 merged 4 commits into
mainfrom
develop

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Promote the branch-scoped self-publishing CI/CD migration to main, cutting the 3.6 stable release.

Carries the develop work: 5-workflow self-publishing pipeline (no codegen), WORKFLOW.md, repo-config/ (rulesets + settings as code), keyless OIDC NuGet publishing, flat Utilities.7z release packaging, reconciled docs, and the 3.6 version floor. The 3.6 prerelease published from develop verified clean (flat archive, NuGet package + symbols pushed).

Merge method is a merge commit (not squash) so main keeps a real reference to develop's commits.

🤖 Generated with Claude Code

dependabotBotand others added 4 commits June 23, 2026 14:55
Updated [Microsoft.NET.Test.Sdk](https://github.com/microsoft/vstest)
from 18.6.0 to 18.7.0.
<details>
<summary>Release notes</summary>
_Sourced from [Microsoft.NET.Test.Sdk's
releases](https://github.com/microsoft/vstest/releases)._
## 18.7.0
## What's Changed
* Add ARM64 msdia140.dll support to test platform packages by
@​jamesmcroft in microsoft/vstest#15689
* Update System.Memory from 4.5.5 to 4.6.3 by @​nohwnd in
microsoft/vstest#15706
## New Contributors
* @​jamesmcroft made their first contribution in
microsoft/vstest#15689
**Full Changelog**:
microsoft/vstest@v18.6.0...v18.7.0
Commits viewable in [compare
view](microsoft/vstest@v18.6.0...v18.7.0).
</details>
[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=Microsoft.NET.Test.Sdk&package-manager=nuget&previous-version=18.6.0&new-version=18.7.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…ce (#344)
Re-syncs this repo's carried governance/config artifacts and CI
orchestration to the current
[ptr727/ProjectTemplate](https://github.com/ptr727/ProjectTemplate)
(template-convergence barrier), and folds in this repo's task list. Held
for maintainer end-gate review - do not auto-merge.
## What this does
- **Carried artifacts re-synced to the template** (adapting only the
sanctioned placeholders): `AGENTS.md` "PR Review Etiquette",
`.github/copilot-instructions.md`, `.markdownlint-cli2.jsonc`,
`.editorconfig`, `.gitattributes`, and `CODESTYLE.md`. The carried files
are byte-for-byte the template's except for the documented adaptations
below. Carried workflow YAML stays CRLF to match the template's
checked-in form (per `.editorconfig`).
- **`CODESTYLE.md` carried whole** (General + .NET + Python). Only the
.NET section is consumed here; the Python section is inert but kept so
re-sync stays a wholesale replace.
- **Orchestration workflows aligned with the template:**
- `build-release-task.yml` / `build-nugetlibrary-task.yml`:
`github-release` decoupled from the build job; the download collects by
`pattern: release-asset-${{ inputs.branch }}-*` + `merge-multiple: true`
with `fail_on_unmatched_files: true`; the NuGet upload is renamed to
`release-asset-<branch>-nugetlibrary` and the unused `artifact-id`
output dropped; adds the main-only prerelease-suffix backstop.
- `merge-bot-pull-request.yml`: concurrency keyed per-PR
(`github.event.pull_request.number`) so bot PRs against the same base
queue independently.
- `publish-release.yml`: dispatch-from-default-branch guard.
- `test-pull-request.yml`: terminal `cleanup-artifacts` job (`needs:
[smoke-build]`), independent of `check-workflow-status` so housekeeping
never gates the required merge check.
## Documented adaptations (for review)
These are the only intentional deviations from the template; everything
else matches it. Sourced from `AGENTS.md` "Template Adaptations".
- **NuGet-only target set.** No Docker, executable, PyPI, or codegen
targets, so the corresponding `build-*-task.yml` / `run-codegen-*.yml`
workflows are absent and the merge-bot carries only the Dependabot path.
`publish-release.yml` keeps its repo-specific per-branch `date-badge`
matrix and omits the template's PyPI/Docker jobs.
- **Husky-driven clean-compile as the CI style gate.** The template
lints style directly in CI; this repo wires Husky.Net as a local
pre-commit gate and runs the same CSharpier + `dotnet format` checks in
CI via `dotnet husky run`, so the local gate and CI run identical
commands. Sanctioned by `CODESTYLE.md` "Clean-Compile Verification".
- **`.husky/pre-commit` LF pin.** `.editorconfig` adds a
`[.husky/pre-commit]` LF block and `.gitattributes` adds
`.husky/pre-commit text eol=lf` (the template's `[*.sh]` / `*.sh` rules
do not match the extensionless hook). Required because this repo ships
the Husky hook.
- **Brownfield analyzer relaxations.** A pre-existing set of analyzer
rules is relaxed to suggestion in `.editorconfig` (and `IL3058` via
`NoWarn`) to keep the published public API stable; each is documented
inline.
Validation: actionlint clean, markdownlint 0 errors, carried-config
diffs vs the template are EOL/adaptation-only.
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…up (#346)
Bumps the actions-deps group with 1 update:
[actions/setup-dotnet](https://github.com/actions/setup-dotnet).
Updates `actions/setup-dotnet` from 5.3.0 to 5.4.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/actions/setup-dotnet/releases">actions/setup-dotnet's
releases</a>.</em></p>
<blockquote>
<h2>v5.4.0</h2>
<h2>What's Changed</h2>
<h3>Enhancements</h3>
<ul>
<li>Improve global.json SDK version validation for rollForward by <a
href="https://github.com/priyagupta108"><code>@​priyagupta108</code></a>
in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/742">actions/setup-dotnet#742</a></li>
<li>Pin actions to commit SHAs in workflows by <a
href="https://github.com/priya-kinthali"><code>@​priya-kinthali</code></a>
in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/744">actions/setup-dotnet#744</a></li>
<li>Expand the CSC problem matcher to light up more errors on GitHub. by
<a
href="https://github.com/StephenCleary"><code>@​StephenCleary</code></a>
in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/717">actions/setup-dotnet#717</a></li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Docs(action): Explicitly mark all optional inputs with required:
false by <a
href="https://github.com/kranthipoturaju"><code>@​kranthipoturaju</code></a>
in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/737">actions/setup-dotnet#737</a></li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li>Fix global.json creation command by <a
href="https://github.com/michal2612"><code>@​michal2612</code></a> in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/694">actions/setup-dotnet#694</a></li>
</ul>
<h3>Dependency Updates</h3>
<ul>
<li>Upgrade <code>@​actions/cache</code> to 5.1.0, log cache write
denied by <a
href="https://github.com/jasongin"><code>@​jasongin</code></a> in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/746">actions/setup-dotnet#746</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/jasongin"><code>@​jasongin</code></a>
made their first contribution in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/746">actions/setup-dotnet#746</a></li>
<li><a
href="https://github.com/michal2612"><code>@​michal2612</code></a> made
their first contribution in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/694">actions/setup-dotnet#694</a></li>
<li><a
href="https://github.com/kranthipoturaju"><code>@​kranthipoturaju</code></a>
made their first contribution in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/737">actions/setup-dotnet#737</a></li>
<li><a
href="https://github.com/StephenCleary"><code>@​StephenCleary</code></a>
made their first contribution in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/717">actions/setup-dotnet#717</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/setup-dotnet/compare/v5...v5.4.0">https://github.com/actions/setup-dotnet/compare/v5...v5.4.0</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/actions/setup-dotnet/commit/26b0ec14cb23fa6904739307f278c14f94c95bf1"><code>26b0ec1</code></a>
Expand the CSC problem matcher to light up more errors on GitHub. (<a
href="https://redirect.github.com/actions/setup-dotnet/issues/717">#717</a>)</li>
<li><a
href="https://github.com/actions/setup-dotnet/commit/da5e5482f2d0700168cff080da45b50da8b60f0e"><code>da5e548</code></a>
docs(action): explicitly mark all optional inputs with required: false
(<a
href="https://redirect.github.com/actions/setup-dotnet/issues/737">#737</a>)</li>
<li><a
href="https://github.com/actions/setup-dotnet/commit/9bd3b44355ba7c500f3d2e029636c6d29ac5caab"><code>9bd3b44</code></a>
Improve readability of global.json creation command (<a
href="https://redirect.github.com/actions/setup-dotnet/issues/694">#694</a>)</li>
<li><a
href="https://github.com/actions/setup-dotnet/commit/4406a635cd2be9c92689ea22b2f74ea57297088c"><code>4406a63</code></a>
Bump <code>@​actions/cache</code> to 5.1.0, log cache write denied (<a
href="https://redirect.github.com/actions/setup-dotnet/issues/746">#746</a>)</li>
<li><a
href="https://github.com/actions/setup-dotnet/commit/dc3262dda80e97f1c7865b3b122e99240e30b738"><code>dc3262d</code></a>
pin actions to commit SHAs in workflows (<a
href="https://redirect.github.com/actions/setup-dotnet/issues/744">#744</a>)</li>
<li><a
href="https://github.com/actions/setup-dotnet/commit/95a3f8b067437dc9b2027a437f5dc3b4569ddd49"><code>95a3f8b</code></a>
Validate global.json SDK version before rollForward optimization (<a
href="https://redirect.github.com/actions/setup-dotnet/issues/742">#742</a>)</li>
<li>See full diff in <a
href="https://github.com/actions/setup-dotnet/compare/9a946fdbd5fb07b82b2f5a4466058b876ab72bb2...26b0ec14cb23fa6904739307f278c14f94c95bf1">compare
view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=actions/setup-dotnet&package-manager=github_actions&previous-version=5.3.0&new-version=5.4.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Ports the branch-scoped self-publishing CI/CD from
`ptr727/LanguageTags`, replacing the ProjectTemplate two-phase model.
`main` publishes stable releases and `develop` publishes prereleases;
each branch publishes itself when a shipped input changes. Utilities has
no codegen, so the generator workflows and merge-bot codegen job are
omitted.
## Workflows
- Remove `build-datebadge-task.yml`, `build-nugetlibrary-task.yml`,
`get-version-task.yml`.
- Add `validate-task.yml` (unit tests + CSharpier / `dotnet format
style` / markdownlint / cspell / actionlint).
- Rework `build-release-task.yml` (NBGV, keyless OIDC `NuGet/login`
push, flat `Utilities.7z` asset), `publish-release.yml` (push/dispatch
self-publisher with a shipped-input inclusion list),
`test-pull-request.yml` (validate + smoke-build + `Check pull request
workflow status job` aggregator), and `merge-bot-pull-request.yml`
(Dependabot auto-merge only).
## Config and docs
- Add `WORKFLOW.md` (canonical CI/CD spec, codegen sections removed) and
`repo-config/` (rulesets + settings as code, `delete_branch_on_merge`
off).
- Add `cspell.json` as the single spell-check source; reconcile
`AGENTS.md`, `CODESTYLE.md`, `.github/copilot-instructions.md`,
`.github/dependabot.yml`, `.vscode/tasks.json`, and `Utilities.slnx`.
- Bump version floor 3.5 -> 3.6; refresh `README.md` and `HISTORY.md`.
Verified locally: actionlint, markdownlint, cspell, YAML/JSON parse,
`bash -n configure.sh`, EOL per `.editorconfig`, and Husky
clean-compile.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 28, 2026 04:37

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Promotes the branch-scoped self-publishing CI/CD model (and related documentation/config-as-code) from develop to main, cutting the 3.6 stable release floor and aligning main with the new workflow contract.

Changes:

  • Introduce a reusable CI validation gate (validate-task.yml) and rework PR + publish workflows around branch-scoped, single-ref releases.
  • Add CI/CD specification and repo configuration-as-code (WORKFLOW.md, repo-config/) and refresh contributing/docs accordingly.
  • Bump the NBGV version floor to 3.6 and apply minor dependency/solution workspace updates.

Reviewed changes

Copilot reviewed 29 out of 29 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
WORKFLOW.mdAdds the canonical CI/CD workflow contract, architecture, and verification methodology.
version.jsonBumps NBGV version floor to 3.6 for the stable release line.
Utilities.slnxUpdates solution items/workflow references to match the new pipeline and docs.
Utilities.code-workspaceRemoves embedded CSpell dictionary in favor of a dedicated cspell.json.
repo-config/settings.jsonCodifies repo-level settings (merge methods, auto-merge, etc.).
repo-config/ruleset-main.jsonCodifies the main branch ruleset (merge-commit-only, required check, signatures).
repo-config/ruleset-develop.jsonCodifies the develop branch ruleset (squash-only/linear history, required check, signatures).
repo-config/README.mdDocuments how the configuration-as-code directory is applied and audited.
repo-config/configure.shAdds an idempotent gh api script to apply/check rulesets, settings, and required secrets.
README.mdUpdates distribution links, badges, and contributing guidance to reflect the new CI/CD model.
HISTORY.mdAdds v3.6 release notes describing the CI/CD and publishing changes.
Directory.Packages.propsUpdates Microsoft.NET.Test.Sdk to 18.7.0.
cspell.jsonAdds a repo-wide CSpell configuration and accepted word list.
CODESTYLE.mdUpdates code-style documentation to reflect current tooling and CI lint behavior.
AGENTS.mdRefactors agent guidance to point to WORKFLOW.md for CI/CD and clarifies review/merge gate expectations.
.vscode/tasks.jsonCleans up task file commentary and clarifies clean-compile vs convenience tasks.
.markdownlint-cli2.jsoncClarifies MD060 policy (table column style) in markdownlint configuration.
.github/workflows/validate-task.ymlAdds reusable validation workflow (unit tests + lint suite).
.github/workflows/test-pull-request.ymlSwitches PR gating to push-based CI for head-resolved workflow self-testing + required aggregator.
.github/workflows/publish-release.ymlReworks publishing to branch-scoped self-publishing on shipped-input changes or dispatch (no schedule).
.github/workflows/merge-bot-pull-request.ymlSimplifies merge-bot logic; enables auto-merge for Dependabot on both branches and disables on maintainer pushes.
.github/workflows/get-version-task.ymlRemoves standalone reusable version task (versioning now inlined into build-release-task).
.github/workflows/build-release-task.ymlConsolidates version/build/publish/release responsibilities; adds OIDC NuGet publishing and flat Utilities.7z asset.
.github/workflows/build-nugetlibrary-task.ymlRemoves legacy build task superseded by build-release-task.
.github/workflows/build-datebadge-task.ymlRemoves decorative date-badge workflow from the pipeline.
.github/dependabot.ymlTightens and shortens rationale comments while keeping dual-target updates.
.github/copilot-instructions.mdMinor wording updates in Copilot runbook and references.
.gitattributesClarifies EOL strategy and pins LF for execution-sensitive script classes.
.editorconfigRefines per-file-type EOL rules and adds ReSharper settings; adjusts C# analyzer settings.

Comment thread.editorconfig
Comment on lines 17 to 21
[*]
charset = utf-8
end_of_line = crlf
indent_size = 4
indent_style = space
insert_final_newline = true
Comment threadCODESTYLE.md
Comment on lines 198 to 202
1. **XML documentation**
- `<GenerateDocumentationFile>true</GenerateDocumentationFile>`
- Document all public surfaces.
- Missing XML comments for public APIs are suppressed (`.editorconfig`)
- Must document all public surfaces.
- Single-line summaries, additional details in remarks, document input parameters, return values, exceptions, and add crefs
@ptr727
ptr727 merged commit 1cbe6b2 into mainJun 28, 2026
17 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Promote develop to main: branch-scoped CI/CD + 3.6 - #350

Merged
ptr727 merged 4 commits into
mainfrom
develop
Jun 28, 2026
Merged

Promote develop to main: branch-scoped CI/CD + 3.6#350
ptr727 merged 4 commits into
mainfrom
develop

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Promote the branch-scoped self-publishing CI/CD migration to main, cutting the 3.6 stable release.

Carries the develop work: 5-workflow self-publishing pipeline (no codegen), WORKFLOW.md, repo-config/ (rulesets + settings as code), keyless OIDC NuGet publishing, flat Utilities.7z release packaging, reconciled docs, and the 3.6 version floor. The 3.6 prerelease published from develop verified clean (flat archive, NuGet package + symbols pushed).

Merge method is a merge commit (not squash) so main keeps a real reference to develop's commits.

🤖 Generated with Claude Code

dependabotBotand others added 4 commits June 23, 2026 14:55
Updated [Microsoft.NET.Test.Sdk](https://github.com/microsoft/vstest)
from 18.6.0 to 18.7.0.
<details>
<summary>Release notes</summary>
_Sourced from [Microsoft.NET.Test.Sdk's
releases](https://github.com/microsoft/vstest/releases)._
## 18.7.0
## What's Changed
* Add ARM64 msdia140.dll support to test platform packages by
@​jamesmcroft in microsoft/vstest#15689
* Update System.Memory from 4.5.5 to 4.6.3 by @​nohwnd in
microsoft/vstest#15706
## New Contributors
* @​jamesmcroft made their first contribution in
microsoft/vstest#15689
**Full Changelog**:
microsoft/vstest@v18.6.0...v18.7.0
Commits viewable in [compare
view](microsoft/vstest@v18.6.0...v18.7.0).
</details>
[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=Microsoft.NET.Test.Sdk&package-manager=nuget&previous-version=18.6.0&new-version=18.7.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…ce (#344)
Re-syncs this repo's carried governance/config artifacts and CI
orchestration to the current
[ptr727/ProjectTemplate](https://github.com/ptr727/ProjectTemplate)
(template-convergence barrier), and folds in this repo's task list. Held
for maintainer end-gate review - do not auto-merge.
## What this does
- **Carried artifacts re-synced to the template** (adapting only the
sanctioned placeholders): `AGENTS.md` "PR Review Etiquette",
`.github/copilot-instructions.md`, `.markdownlint-cli2.jsonc`,
`.editorconfig`, `.gitattributes`, and `CODESTYLE.md`. The carried files
are byte-for-byte the template's except for the documented adaptations
below. Carried workflow YAML stays CRLF to match the template's
checked-in form (per `.editorconfig`).
- **`CODESTYLE.md` carried whole** (General + .NET + Python). Only the
.NET section is consumed here; the Python section is inert but kept so
re-sync stays a wholesale replace.
- **Orchestration workflows aligned with the template:**
- `build-release-task.yml` / `build-nugetlibrary-task.yml`:
`github-release` decoupled from the build job; the download collects by
`pattern: release-asset-${{ inputs.branch }}-*` + `merge-multiple: true`
with `fail_on_unmatched_files: true`; the NuGet upload is renamed to
`release-asset-<branch>-nugetlibrary` and the unused `artifact-id`
output dropped; adds the main-only prerelease-suffix backstop.
- `merge-bot-pull-request.yml`: concurrency keyed per-PR
(`github.event.pull_request.number`) so bot PRs against the same base
queue independently.
- `publish-release.yml`: dispatch-from-default-branch guard.
- `test-pull-request.yml`: terminal `cleanup-artifacts` job (`needs:
[smoke-build]`), independent of `check-workflow-status` so housekeeping
never gates the required merge check.
## Documented adaptations (for review)
These are the only intentional deviations from the template; everything
else matches it. Sourced from `AGENTS.md` "Template Adaptations".
- **NuGet-only target set.** No Docker, executable, PyPI, or codegen
targets, so the corresponding `build-*-task.yml` / `run-codegen-*.yml`
workflows are absent and the merge-bot carries only the Dependabot path.
`publish-release.yml` keeps its repo-specific per-branch `date-badge`
matrix and omits the template's PyPI/Docker jobs.
- **Husky-driven clean-compile as the CI style gate.** The template
lints style directly in CI; this repo wires Husky.Net as a local
pre-commit gate and runs the same CSharpier + `dotnet format` checks in
CI via `dotnet husky run`, so the local gate and CI run identical
commands. Sanctioned by `CODESTYLE.md` "Clean-Compile Verification".
- **`.husky/pre-commit` LF pin.** `.editorconfig` adds a
`[.husky/pre-commit]` LF block and `.gitattributes` adds
`.husky/pre-commit text eol=lf` (the template's `[*.sh]` / `*.sh` rules
do not match the extensionless hook). Required because this repo ships
the Husky hook.
- **Brownfield analyzer relaxations.** A pre-existing set of analyzer
rules is relaxed to suggestion in `.editorconfig` (and `IL3058` via
`NoWarn`) to keep the published public API stable; each is documented
inline.
Validation: actionlint clean, markdownlint 0 errors, carried-config
diffs vs the template are EOL/adaptation-only.
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…up (#346)
Bumps the actions-deps group with 1 update:
[actions/setup-dotnet](https://github.com/actions/setup-dotnet).
Updates `actions/setup-dotnet` from 5.3.0 to 5.4.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/actions/setup-dotnet/releases">actions/setup-dotnet's
releases</a>.</em></p>
<blockquote>
<h2>v5.4.0</h2>
<h2>What's Changed</h2>
<h3>Enhancements</h3>
<ul>
<li>Improve global.json SDK version validation for rollForward by <a
href="https://github.com/priyagupta108"><code>@​priyagupta108</code></a>
in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/742">actions/setup-dotnet#742</a></li>
<li>Pin actions to commit SHAs in workflows by <a
href="https://github.com/priya-kinthali"><code>@​priya-kinthali</code></a>
in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/744">actions/setup-dotnet#744</a></li>
<li>Expand the CSC problem matcher to light up more errors on GitHub. by
<a
href="https://github.com/StephenCleary"><code>@​StephenCleary</code></a>
in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/717">actions/setup-dotnet#717</a></li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Docs(action): Explicitly mark all optional inputs with required:
false by <a
href="https://github.com/kranthipoturaju"><code>@​kranthipoturaju</code></a>
in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/737">actions/setup-dotnet#737</a></li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li>Fix global.json creation command by <a
href="https://github.com/michal2612"><code>@​michal2612</code></a> in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/694">actions/setup-dotnet#694</a></li>
</ul>
<h3>Dependency Updates</h3>
<ul>
<li>Upgrade <code>@​actions/cache</code> to 5.1.0, log cache write
denied by <a
href="https://github.com/jasongin"><code>@​jasongin</code></a> in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/746">actions/setup-dotnet#746</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/jasongin"><code>@​jasongin</code></a>
made their first contribution in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/746">actions/setup-dotnet#746</a></li>
<li><a
href="https://github.com/michal2612"><code>@​michal2612</code></a> made
their first contribution in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/694">actions/setup-dotnet#694</a></li>
<li><a
href="https://github.com/kranthipoturaju"><code>@​kranthipoturaju</code></a>
made their first contribution in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/737">actions/setup-dotnet#737</a></li>
<li><a
href="https://github.com/StephenCleary"><code>@​StephenCleary</code></a>
made their first contribution in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/717">actions/setup-dotnet#717</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/setup-dotnet/compare/v5...v5.4.0">https://github.com/actions/setup-dotnet/compare/v5...v5.4.0</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/actions/setup-dotnet/commit/26b0ec14cb23fa6904739307f278c14f94c95bf1"><code>26b0ec1</code></a>
Expand the CSC problem matcher to light up more errors on GitHub. (<a
href="https://redirect.github.com/actions/setup-dotnet/issues/717">#717</a>)</li>
<li><a
href="https://github.com/actions/setup-dotnet/commit/da5e5482f2d0700168cff080da45b50da8b60f0e"><code>da5e548</code></a>
docs(action): explicitly mark all optional inputs with required: false
(<a
href="https://redirect.github.com/actions/setup-dotnet/issues/737">#737</a>)</li>
<li><a
href="https://github.com/actions/setup-dotnet/commit/9bd3b44355ba7c500f3d2e029636c6d29ac5caab"><code>9bd3b44</code></a>
Improve readability of global.json creation command (<a
href="https://redirect.github.com/actions/setup-dotnet/issues/694">#694</a>)</li>
<li><a
href="https://github.com/actions/setup-dotnet/commit/4406a635cd2be9c92689ea22b2f74ea57297088c"><code>4406a63</code></a>
Bump <code>@​actions/cache</code> to 5.1.0, log cache write denied (<a
href="https://redirect.github.com/actions/setup-dotnet/issues/746">#746</a>)</li>
<li><a
href="https://github.com/actions/setup-dotnet/commit/dc3262dda80e97f1c7865b3b122e99240e30b738"><code>dc3262d</code></a>
pin actions to commit SHAs in workflows (<a
href="https://redirect.github.com/actions/setup-dotnet/issues/744">#744</a>)</li>
<li><a
href="https://github.com/actions/setup-dotnet/commit/95a3f8b067437dc9b2027a437f5dc3b4569ddd49"><code>95a3f8b</code></a>
Validate global.json SDK version before rollForward optimization (<a
href="https://redirect.github.com/actions/setup-dotnet/issues/742">#742</a>)</li>
<li>See full diff in <a
href="https://github.com/actions/setup-dotnet/compare/9a946fdbd5fb07b82b2f5a4466058b876ab72bb2...26b0ec14cb23fa6904739307f278c14f94c95bf1">compare
view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=actions/setup-dotnet&package-manager=github_actions&previous-version=5.3.0&new-version=5.4.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Ports the branch-scoped self-publishing CI/CD from
`ptr727/LanguageTags`, replacing the ProjectTemplate two-phase model.
`main` publishes stable releases and `develop` publishes prereleases;
each branch publishes itself when a shipped input changes. Utilities has
no codegen, so the generator workflows and merge-bot codegen job are
omitted.
## Workflows
- Remove `build-datebadge-task.yml`, `build-nugetlibrary-task.yml`,
`get-version-task.yml`.
- Add `validate-task.yml` (unit tests + CSharpier / `dotnet format
style` / markdownlint / cspell / actionlint).
- Rework `build-release-task.yml` (NBGV, keyless OIDC `NuGet/login`
push, flat `Utilities.7z` asset), `publish-release.yml` (push/dispatch
self-publisher with a shipped-input inclusion list),
`test-pull-request.yml` (validate + smoke-build + `Check pull request
workflow status job` aggregator), and `merge-bot-pull-request.yml`
(Dependabot auto-merge only).
## Config and docs
- Add `WORKFLOW.md` (canonical CI/CD spec, codegen sections removed) and
`repo-config/` (rulesets + settings as code, `delete_branch_on_merge`
off).
- Add `cspell.json` as the single spell-check source; reconcile
`AGENTS.md`, `CODESTYLE.md`, `.github/copilot-instructions.md`,
`.github/dependabot.yml`, `.vscode/tasks.json`, and `Utilities.slnx`.
- Bump version floor 3.5 -> 3.6; refresh `README.md` and `HISTORY.md`.
Verified locally: actionlint, markdownlint, cspell, YAML/JSON parse,
`bash -n configure.sh`, EOL per `.editorconfig`, and Husky
clean-compile.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 28, 2026 04:37

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Promotes the branch-scoped self-publishing CI/CD model (and related documentation/config-as-code) from develop to main, cutting the 3.6 stable release floor and aligning main with the new workflow contract.

Changes:

  • Introduce a reusable CI validation gate (validate-task.yml) and rework PR + publish workflows around branch-scoped, single-ref releases.
  • Add CI/CD specification and repo configuration-as-code (WORKFLOW.md, repo-config/) and refresh contributing/docs accordingly.
  • Bump the NBGV version floor to 3.6 and apply minor dependency/solution workspace updates.

Reviewed changes

Copilot reviewed 29 out of 29 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
WORKFLOW.mdAdds the canonical CI/CD workflow contract, architecture, and verification methodology.
version.jsonBumps NBGV version floor to 3.6 for the stable release line.
Utilities.slnxUpdates solution items/workflow references to match the new pipeline and docs.
Utilities.code-workspaceRemoves embedded CSpell dictionary in favor of a dedicated cspell.json.
repo-config/settings.jsonCodifies repo-level settings (merge methods, auto-merge, etc.).
repo-config/ruleset-main.jsonCodifies the main branch ruleset (merge-commit-only, required check, signatures).
repo-config/ruleset-develop.jsonCodifies the develop branch ruleset (squash-only/linear history, required check, signatures).
repo-config/README.mdDocuments how the configuration-as-code directory is applied and audited.
repo-config/configure.shAdds an idempotent gh api script to apply/check rulesets, settings, and required secrets.
README.mdUpdates distribution links, badges, and contributing guidance to reflect the new CI/CD model.
HISTORY.mdAdds v3.6 release notes describing the CI/CD and publishing changes.
Directory.Packages.propsUpdates Microsoft.NET.Test.Sdk to 18.7.0.
cspell.jsonAdds a repo-wide CSpell configuration and accepted word list.
CODESTYLE.mdUpdates code-style documentation to reflect current tooling and CI lint behavior.
AGENTS.mdRefactors agent guidance to point to WORKFLOW.md for CI/CD and clarifies review/merge gate expectations.
.vscode/tasks.jsonCleans up task file commentary and clarifies clean-compile vs convenience tasks.
.markdownlint-cli2.jsoncClarifies MD060 policy (table column style) in markdownlint configuration.
.github/workflows/validate-task.ymlAdds reusable validation workflow (unit tests + lint suite).
.github/workflows/test-pull-request.ymlSwitches PR gating to push-based CI for head-resolved workflow self-testing + required aggregator.
.github/workflows/publish-release.ymlReworks publishing to branch-scoped self-publishing on shipped-input changes or dispatch (no schedule).
.github/workflows/merge-bot-pull-request.ymlSimplifies merge-bot logic; enables auto-merge for Dependabot on both branches and disables on maintainer pushes.
.github/workflows/get-version-task.ymlRemoves standalone reusable version task (versioning now inlined into build-release-task).
.github/workflows/build-release-task.ymlConsolidates version/build/publish/release responsibilities; adds OIDC NuGet publishing and flat Utilities.7z asset.
.github/workflows/build-nugetlibrary-task.ymlRemoves legacy build task superseded by build-release-task.
.github/workflows/build-datebadge-task.ymlRemoves decorative date-badge workflow from the pipeline.
.github/dependabot.ymlTightens and shortens rationale comments while keeping dual-target updates.
.github/copilot-instructions.mdMinor wording updates in Copilot runbook and references.
.gitattributesClarifies EOL strategy and pins LF for execution-sensitive script classes.
.editorconfigRefines per-file-type EOL rules and adds ReSharper settings; adjusts C# analyzer settings.

Comment thread.editorconfig
Comment on lines 17 to 21
[*]
charset = utf-8
end_of_line = crlf
indent_size = 4
indent_style = space
insert_final_newline = true
Comment threadCODESTYLE.md
Comment on lines 198 to 202
1. **XML documentation**
- `<GenerateDocumentationFile>true</GenerateDocumentationFile>`
- Document all public surfaces.
- Missing XML comments for public APIs are suppressed (`.editorconfig`)
- Must document all public surfaces.
- Single-line summaries, additional details in remarks, document input parameters, return values, exceptions, and add crefs
@ptr727
ptr727 merged commit 1cbe6b2 into mainJun 28, 2026
17 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Promote develop to main: branch-scoped CI/CD + 3.6 - #350

Merged
ptr727 merged 4 commits into
mainfrom
develop
Jun 28, 2026
Merged

Promote develop to main: branch-scoped CI/CD + 3.6#350
ptr727 merged 4 commits into
mainfrom
develop

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Promote the branch-scoped self-publishing CI/CD migration to main, cutting the 3.6 stable release.

Carries the develop work: 5-workflow self-publishing pipeline (no codegen), WORKFLOW.md, repo-config/ (rulesets + settings as code), keyless OIDC NuGet publishing, flat Utilities.7z release packaging, reconciled docs, and the 3.6 version floor. The 3.6 prerelease published from develop verified clean (flat archive, NuGet package + symbols pushed).

Merge method is a merge commit (not squash) so main keeps a real reference to develop's commits.

🤖 Generated with Claude Code

dependabotBotand others added 4 commits June 23, 2026 14:55
Updated [Microsoft.NET.Test.Sdk](https://github.com/microsoft/vstest)
from 18.6.0 to 18.7.0.
<details>
<summary>Release notes</summary>
_Sourced from [Microsoft.NET.Test.Sdk's
releases](https://github.com/microsoft/vstest/releases)._
## 18.7.0
## What's Changed
* Add ARM64 msdia140.dll support to test platform packages by
@​jamesmcroft in microsoft/vstest#15689
* Update System.Memory from 4.5.5 to 4.6.3 by @​nohwnd in
microsoft/vstest#15706
## New Contributors
* @​jamesmcroft made their first contribution in
microsoft/vstest#15689
**Full Changelog**:
microsoft/vstest@v18.6.0...v18.7.0
Commits viewable in [compare
view](microsoft/vstest@v18.6.0...v18.7.0).
</details>
[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=Microsoft.NET.Test.Sdk&package-manager=nuget&previous-version=18.6.0&new-version=18.7.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…ce (#344)
Re-syncs this repo's carried governance/config artifacts and CI
orchestration to the current
[ptr727/ProjectTemplate](https://github.com/ptr727/ProjectTemplate)
(template-convergence barrier), and folds in this repo's task list. Held
for maintainer end-gate review - do not auto-merge.
## What this does
- **Carried artifacts re-synced to the template** (adapting only the
sanctioned placeholders): `AGENTS.md` "PR Review Etiquette",
`.github/copilot-instructions.md`, `.markdownlint-cli2.jsonc`,
`.editorconfig`, `.gitattributes`, and `CODESTYLE.md`. The carried files
are byte-for-byte the template's except for the documented adaptations
below. Carried workflow YAML stays CRLF to match the template's
checked-in form (per `.editorconfig`).
- **`CODESTYLE.md` carried whole** (General + .NET + Python). Only the
.NET section is consumed here; the Python section is inert but kept so
re-sync stays a wholesale replace.
- **Orchestration workflows aligned with the template:**
- `build-release-task.yml` / `build-nugetlibrary-task.yml`:
`github-release` decoupled from the build job; the download collects by
`pattern: release-asset-${{ inputs.branch }}-*` + `merge-multiple: true`
with `fail_on_unmatched_files: true`; the NuGet upload is renamed to
`release-asset-<branch>-nugetlibrary` and the unused `artifact-id`
output dropped; adds the main-only prerelease-suffix backstop.
- `merge-bot-pull-request.yml`: concurrency keyed per-PR
(`github.event.pull_request.number`) so bot PRs against the same base
queue independently.
- `publish-release.yml`: dispatch-from-default-branch guard.
- `test-pull-request.yml`: terminal `cleanup-artifacts` job (`needs:
[smoke-build]`), independent of `check-workflow-status` so housekeeping
never gates the required merge check.
## Documented adaptations (for review)
These are the only intentional deviations from the template; everything
else matches it. Sourced from `AGENTS.md` "Template Adaptations".
- **NuGet-only target set.** No Docker, executable, PyPI, or codegen
targets, so the corresponding `build-*-task.yml` / `run-codegen-*.yml`
workflows are absent and the merge-bot carries only the Dependabot path.
`publish-release.yml` keeps its repo-specific per-branch `date-badge`
matrix and omits the template's PyPI/Docker jobs.
- **Husky-driven clean-compile as the CI style gate.** The template
lints style directly in CI; this repo wires Husky.Net as a local
pre-commit gate and runs the same CSharpier + `dotnet format` checks in
CI via `dotnet husky run`, so the local gate and CI run identical
commands. Sanctioned by `CODESTYLE.md` "Clean-Compile Verification".
- **`.husky/pre-commit` LF pin.** `.editorconfig` adds a
`[.husky/pre-commit]` LF block and `.gitattributes` adds
`.husky/pre-commit text eol=lf` (the template's `[*.sh]` / `*.sh` rules
do not match the extensionless hook). Required because this repo ships
the Husky hook.
- **Brownfield analyzer relaxations.** A pre-existing set of analyzer
rules is relaxed to suggestion in `.editorconfig` (and `IL3058` via
`NoWarn`) to keep the published public API stable; each is documented
inline.
Validation: actionlint clean, markdownlint 0 errors, carried-config
diffs vs the template are EOL/adaptation-only.
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…up (#346)
Bumps the actions-deps group with 1 update:
[actions/setup-dotnet](https://github.com/actions/setup-dotnet).
Updates `actions/setup-dotnet` from 5.3.0 to 5.4.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/actions/setup-dotnet/releases">actions/setup-dotnet's
releases</a>.</em></p>
<blockquote>
<h2>v5.4.0</h2>
<h2>What's Changed</h2>
<h3>Enhancements</h3>
<ul>
<li>Improve global.json SDK version validation for rollForward by <a
href="https://github.com/priyagupta108"><code>@​priyagupta108</code></a>
in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/742">actions/setup-dotnet#742</a></li>
<li>Pin actions to commit SHAs in workflows by <a
href="https://github.com/priya-kinthali"><code>@​priya-kinthali</code></a>
in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/744">actions/setup-dotnet#744</a></li>
<li>Expand the CSC problem matcher to light up more errors on GitHub. by
<a
href="https://github.com/StephenCleary"><code>@​StephenCleary</code></a>
in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/717">actions/setup-dotnet#717</a></li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Docs(action): Explicitly mark all optional inputs with required:
false by <a
href="https://github.com/kranthipoturaju"><code>@​kranthipoturaju</code></a>
in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/737">actions/setup-dotnet#737</a></li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li>Fix global.json creation command by <a
href="https://github.com/michal2612"><code>@​michal2612</code></a> in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/694">actions/setup-dotnet#694</a></li>
</ul>
<h3>Dependency Updates</h3>
<ul>
<li>Upgrade <code>@​actions/cache</code> to 5.1.0, log cache write
denied by <a
href="https://github.com/jasongin"><code>@​jasongin</code></a> in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/746">actions/setup-dotnet#746</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/jasongin"><code>@​jasongin</code></a>
made their first contribution in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/746">actions/setup-dotnet#746</a></li>
<li><a
href="https://github.com/michal2612"><code>@​michal2612</code></a> made
their first contribution in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/694">actions/setup-dotnet#694</a></li>
<li><a
href="https://github.com/kranthipoturaju"><code>@​kranthipoturaju</code></a>
made their first contribution in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/737">actions/setup-dotnet#737</a></li>
<li><a
href="https://github.com/StephenCleary"><code>@​StephenCleary</code></a>
made their first contribution in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/717">actions/setup-dotnet#717</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/setup-dotnet/compare/v5...v5.4.0">https://github.com/actions/setup-dotnet/compare/v5...v5.4.0</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/actions/setup-dotnet/commit/26b0ec14cb23fa6904739307f278c14f94c95bf1"><code>26b0ec1</code></a>
Expand the CSC problem matcher to light up more errors on GitHub. (<a
href="https://redirect.github.com/actions/setup-dotnet/issues/717">#717</a>)</li>
<li><a
href="https://github.com/actions/setup-dotnet/commit/da5e5482f2d0700168cff080da45b50da8b60f0e"><code>da5e548</code></a>
docs(action): explicitly mark all optional inputs with required: false
(<a
href="https://redirect.github.com/actions/setup-dotnet/issues/737">#737</a>)</li>
<li><a
href="https://github.com/actions/setup-dotnet/commit/9bd3b44355ba7c500f3d2e029636c6d29ac5caab"><code>9bd3b44</code></a>
Improve readability of global.json creation command (<a
href="https://redirect.github.com/actions/setup-dotnet/issues/694">#694</a>)</li>
<li><a
href="https://github.com/actions/setup-dotnet/commit/4406a635cd2be9c92689ea22b2f74ea57297088c"><code>4406a63</code></a>
Bump <code>@​actions/cache</code> to 5.1.0, log cache write denied (<a
href="https://redirect.github.com/actions/setup-dotnet/issues/746">#746</a>)</li>
<li><a
href="https://github.com/actions/setup-dotnet/commit/dc3262dda80e97f1c7865b3b122e99240e30b738"><code>dc3262d</code></a>
pin actions to commit SHAs in workflows (<a
href="https://redirect.github.com/actions/setup-dotnet/issues/744">#744</a>)</li>
<li><a
href="https://github.com/actions/setup-dotnet/commit/95a3f8b067437dc9b2027a437f5dc3b4569ddd49"><code>95a3f8b</code></a>
Validate global.json SDK version before rollForward optimization (<a
href="https://redirect.github.com/actions/setup-dotnet/issues/742">#742</a>)</li>
<li>See full diff in <a
href="https://github.com/actions/setup-dotnet/compare/9a946fdbd5fb07b82b2f5a4466058b876ab72bb2...26b0ec14cb23fa6904739307f278c14f94c95bf1">compare
view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=actions/setup-dotnet&package-manager=github_actions&previous-version=5.3.0&new-version=5.4.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Ports the branch-scoped self-publishing CI/CD from
`ptr727/LanguageTags`, replacing the ProjectTemplate two-phase model.
`main` publishes stable releases and `develop` publishes prereleases;
each branch publishes itself when a shipped input changes. Utilities has
no codegen, so the generator workflows and merge-bot codegen job are
omitted.
## Workflows
- Remove `build-datebadge-task.yml`, `build-nugetlibrary-task.yml`,
`get-version-task.yml`.
- Add `validate-task.yml` (unit tests + CSharpier / `dotnet format
style` / markdownlint / cspell / actionlint).
- Rework `build-release-task.yml` (NBGV, keyless OIDC `NuGet/login`
push, flat `Utilities.7z` asset), `publish-release.yml` (push/dispatch
self-publisher with a shipped-input inclusion list),
`test-pull-request.yml` (validate + smoke-build + `Check pull request
workflow status job` aggregator), and `merge-bot-pull-request.yml`
(Dependabot auto-merge only).
## Config and docs
- Add `WORKFLOW.md` (canonical CI/CD spec, codegen sections removed) and
`repo-config/` (rulesets + settings as code, `delete_branch_on_merge`
off).
- Add `cspell.json` as the single spell-check source; reconcile
`AGENTS.md`, `CODESTYLE.md`, `.github/copilot-instructions.md`,
`.github/dependabot.yml`, `.vscode/tasks.json`, and `Utilities.slnx`.
- Bump version floor 3.5 -> 3.6; refresh `README.md` and `HISTORY.md`.
Verified locally: actionlint, markdownlint, cspell, YAML/JSON parse,
`bash -n configure.sh`, EOL per `.editorconfig`, and Husky
clean-compile.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 28, 2026 04:37

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Promotes the branch-scoped self-publishing CI/CD model (and related documentation/config-as-code) from develop to main, cutting the 3.6 stable release floor and aligning main with the new workflow contract.

Changes:

  • Introduce a reusable CI validation gate (validate-task.yml) and rework PR + publish workflows around branch-scoped, single-ref releases.
  • Add CI/CD specification and repo configuration-as-code (WORKFLOW.md, repo-config/) and refresh contributing/docs accordingly.
  • Bump the NBGV version floor to 3.6 and apply minor dependency/solution workspace updates.

Reviewed changes

Copilot reviewed 29 out of 29 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
WORKFLOW.mdAdds the canonical CI/CD workflow contract, architecture, and verification methodology.
version.jsonBumps NBGV version floor to 3.6 for the stable release line.
Utilities.slnxUpdates solution items/workflow references to match the new pipeline and docs.
Utilities.code-workspaceRemoves embedded CSpell dictionary in favor of a dedicated cspell.json.
repo-config/settings.jsonCodifies repo-level settings (merge methods, auto-merge, etc.).
repo-config/ruleset-main.jsonCodifies the main branch ruleset (merge-commit-only, required check, signatures).
repo-config/ruleset-develop.jsonCodifies the develop branch ruleset (squash-only/linear history, required check, signatures).
repo-config/README.mdDocuments how the configuration-as-code directory is applied and audited.
repo-config/configure.shAdds an idempotent gh api script to apply/check rulesets, settings, and required secrets.
README.mdUpdates distribution links, badges, and contributing guidance to reflect the new CI/CD model.
HISTORY.mdAdds v3.6 release notes describing the CI/CD and publishing changes.
Directory.Packages.propsUpdates Microsoft.NET.Test.Sdk to 18.7.0.
cspell.jsonAdds a repo-wide CSpell configuration and accepted word list.
CODESTYLE.mdUpdates code-style documentation to reflect current tooling and CI lint behavior.
AGENTS.mdRefactors agent guidance to point to WORKFLOW.md for CI/CD and clarifies review/merge gate expectations.
.vscode/tasks.jsonCleans up task file commentary and clarifies clean-compile vs convenience tasks.
.markdownlint-cli2.jsoncClarifies MD060 policy (table column style) in markdownlint configuration.
.github/workflows/validate-task.ymlAdds reusable validation workflow (unit tests + lint suite).
.github/workflows/test-pull-request.ymlSwitches PR gating to push-based CI for head-resolved workflow self-testing + required aggregator.
.github/workflows/publish-release.ymlReworks publishing to branch-scoped self-publishing on shipped-input changes or dispatch (no schedule).
.github/workflows/merge-bot-pull-request.ymlSimplifies merge-bot logic; enables auto-merge for Dependabot on both branches and disables on maintainer pushes.
.github/workflows/get-version-task.ymlRemoves standalone reusable version task (versioning now inlined into build-release-task).
.github/workflows/build-release-task.ymlConsolidates version/build/publish/release responsibilities; adds OIDC NuGet publishing and flat Utilities.7z asset.
.github/workflows/build-nugetlibrary-task.ymlRemoves legacy build task superseded by build-release-task.
.github/workflows/build-datebadge-task.ymlRemoves decorative date-badge workflow from the pipeline.
.github/dependabot.ymlTightens and shortens rationale comments while keeping dual-target updates.
.github/copilot-instructions.mdMinor wording updates in Copilot runbook and references.
.gitattributesClarifies EOL strategy and pins LF for execution-sensitive script classes.
.editorconfigRefines per-file-type EOL rules and adds ReSharper settings; adjusts C# analyzer settings.

Comment thread.editorconfig
Comment on lines 17 to 21
[*]
charset = utf-8
end_of_line = crlf
indent_size = 4
indent_style = space
insert_final_newline = true
Comment threadCODESTYLE.md
Comment on lines 198 to 202
1. **XML documentation**
- `<GenerateDocumentationFile>true</GenerateDocumentationFile>`
- Document all public surfaces.
- Missing XML comments for public APIs are suppressed (`.editorconfig`)
- Must document all public surfaces.
- Single-line summaries, additional details in remarks, document input parameters, return values, exceptions, and add crefs
@ptr727
ptr727 merged commit 1cbe6b2 into mainJun 28, 2026
17 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Promote develop to main: branch-scoped CI/CD + 3.6 - #350

Merged
ptr727 merged 4 commits into
mainfrom
develop
Jun 28, 2026
Merged

Promote develop to main: branch-scoped CI/CD + 3.6#350
ptr727 merged 4 commits into
mainfrom
develop

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Promote the branch-scoped self-publishing CI/CD migration to main, cutting the 3.6 stable release.

Carries the develop work: 5-workflow self-publishing pipeline (no codegen), WORKFLOW.md, repo-config/ (rulesets + settings as code), keyless OIDC NuGet publishing, flat Utilities.7z release packaging, reconciled docs, and the 3.6 version floor. The 3.6 prerelease published from develop verified clean (flat archive, NuGet package + symbols pushed).

Merge method is a merge commit (not squash) so main keeps a real reference to develop's commits.

🤖 Generated with Claude Code

dependabotBotand others added 4 commits June 23, 2026 14:55
Updated [Microsoft.NET.Test.Sdk](https://github.com/microsoft/vstest)
from 18.6.0 to 18.7.0.
<details>
<summary>Release notes</summary>
_Sourced from [Microsoft.NET.Test.Sdk's
releases](https://github.com/microsoft/vstest/releases)._
## 18.7.0
## What's Changed
* Add ARM64 msdia140.dll support to test platform packages by
@​jamesmcroft in microsoft/vstest#15689
* Update System.Memory from 4.5.5 to 4.6.3 by @​nohwnd in
microsoft/vstest#15706
## New Contributors
* @​jamesmcroft made their first contribution in
microsoft/vstest#15689
**Full Changelog**:
microsoft/vstest@v18.6.0...v18.7.0
Commits viewable in [compare
view](microsoft/vstest@v18.6.0...v18.7.0).
</details>
[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=Microsoft.NET.Test.Sdk&package-manager=nuget&previous-version=18.6.0&new-version=18.7.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…ce (#344)
Re-syncs this repo's carried governance/config artifacts and CI
orchestration to the current
[ptr727/ProjectTemplate](https://github.com/ptr727/ProjectTemplate)
(template-convergence barrier), and folds in this repo's task list. Held
for maintainer end-gate review - do not auto-merge.
## What this does
- **Carried artifacts re-synced to the template** (adapting only the
sanctioned placeholders): `AGENTS.md` "PR Review Etiquette",
`.github/copilot-instructions.md`, `.markdownlint-cli2.jsonc`,
`.editorconfig`, `.gitattributes`, and `CODESTYLE.md`. The carried files
are byte-for-byte the template's except for the documented adaptations
below. Carried workflow YAML stays CRLF to match the template's
checked-in form (per `.editorconfig`).
- **`CODESTYLE.md` carried whole** (General + .NET + Python). Only the
.NET section is consumed here; the Python section is inert but kept so
re-sync stays a wholesale replace.
- **Orchestration workflows aligned with the template:**
- `build-release-task.yml` / `build-nugetlibrary-task.yml`:
`github-release` decoupled from the build job; the download collects by
`pattern: release-asset-${{ inputs.branch }}-*` + `merge-multiple: true`
with `fail_on_unmatched_files: true`; the NuGet upload is renamed to
`release-asset-<branch>-nugetlibrary` and the unused `artifact-id`
output dropped; adds the main-only prerelease-suffix backstop.
- `merge-bot-pull-request.yml`: concurrency keyed per-PR
(`github.event.pull_request.number`) so bot PRs against the same base
queue independently.
- `publish-release.yml`: dispatch-from-default-branch guard.
- `test-pull-request.yml`: terminal `cleanup-artifacts` job (`needs:
[smoke-build]`), independent of `check-workflow-status` so housekeeping
never gates the required merge check.
## Documented adaptations (for review)
These are the only intentional deviations from the template; everything
else matches it. Sourced from `AGENTS.md` "Template Adaptations".
- **NuGet-only target set.** No Docker, executable, PyPI, or codegen
targets, so the corresponding `build-*-task.yml` / `run-codegen-*.yml`
workflows are absent and the merge-bot carries only the Dependabot path.
`publish-release.yml` keeps its repo-specific per-branch `date-badge`
matrix and omits the template's PyPI/Docker jobs.
- **Husky-driven clean-compile as the CI style gate.** The template
lints style directly in CI; this repo wires Husky.Net as a local
pre-commit gate and runs the same CSharpier + `dotnet format` checks in
CI via `dotnet husky run`, so the local gate and CI run identical
commands. Sanctioned by `CODESTYLE.md` "Clean-Compile Verification".
- **`.husky/pre-commit` LF pin.** `.editorconfig` adds a
`[.husky/pre-commit]` LF block and `.gitattributes` adds
`.husky/pre-commit text eol=lf` (the template's `[*.sh]` / `*.sh` rules
do not match the extensionless hook). Required because this repo ships
the Husky hook.
- **Brownfield analyzer relaxations.** A pre-existing set of analyzer
rules is relaxed to suggestion in `.editorconfig` (and `IL3058` via
`NoWarn`) to keep the published public API stable; each is documented
inline.
Validation: actionlint clean, markdownlint 0 errors, carried-config
diffs vs the template are EOL/adaptation-only.
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…up (#346)
Bumps the actions-deps group with 1 update:
[actions/setup-dotnet](https://github.com/actions/setup-dotnet).
Updates `actions/setup-dotnet` from 5.3.0 to 5.4.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/actions/setup-dotnet/releases">actions/setup-dotnet's
releases</a>.</em></p>
<blockquote>
<h2>v5.4.0</h2>
<h2>What's Changed</h2>
<h3>Enhancements</h3>
<ul>
<li>Improve global.json SDK version validation for rollForward by <a
href="https://github.com/priyagupta108"><code>@​priyagupta108</code></a>
in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/742">actions/setup-dotnet#742</a></li>
<li>Pin actions to commit SHAs in workflows by <a
href="https://github.com/priya-kinthali"><code>@​priya-kinthali</code></a>
in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/744">actions/setup-dotnet#744</a></li>
<li>Expand the CSC problem matcher to light up more errors on GitHub. by
<a
href="https://github.com/StephenCleary"><code>@​StephenCleary</code></a>
in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/717">actions/setup-dotnet#717</a></li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Docs(action): Explicitly mark all optional inputs with required:
false by <a
href="https://github.com/kranthipoturaju"><code>@​kranthipoturaju</code></a>
in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/737">actions/setup-dotnet#737</a></li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li>Fix global.json creation command by <a
href="https://github.com/michal2612"><code>@​michal2612</code></a> in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/694">actions/setup-dotnet#694</a></li>
</ul>
<h3>Dependency Updates</h3>
<ul>
<li>Upgrade <code>@​actions/cache</code> to 5.1.0, log cache write
denied by <a
href="https://github.com/jasongin"><code>@​jasongin</code></a> in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/746">actions/setup-dotnet#746</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/jasongin"><code>@​jasongin</code></a>
made their first contribution in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/746">actions/setup-dotnet#746</a></li>
<li><a
href="https://github.com/michal2612"><code>@​michal2612</code></a> made
their first contribution in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/694">actions/setup-dotnet#694</a></li>
<li><a
href="https://github.com/kranthipoturaju"><code>@​kranthipoturaju</code></a>
made their first contribution in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/737">actions/setup-dotnet#737</a></li>
<li><a
href="https://github.com/StephenCleary"><code>@​StephenCleary</code></a>
made their first contribution in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/717">actions/setup-dotnet#717</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/setup-dotnet/compare/v5...v5.4.0">https://github.com/actions/setup-dotnet/compare/v5...v5.4.0</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/actions/setup-dotnet/commit/26b0ec14cb23fa6904739307f278c14f94c95bf1"><code>26b0ec1</code></a>
Expand the CSC problem matcher to light up more errors on GitHub. (<a
href="https://redirect.github.com/actions/setup-dotnet/issues/717">#717</a>)</li>
<li><a
href="https://github.com/actions/setup-dotnet/commit/da5e5482f2d0700168cff080da45b50da8b60f0e"><code>da5e548</code></a>
docs(action): explicitly mark all optional inputs with required: false
(<a
href="https://redirect.github.com/actions/setup-dotnet/issues/737">#737</a>)</li>
<li><a
href="https://github.com/actions/setup-dotnet/commit/9bd3b44355ba7c500f3d2e029636c6d29ac5caab"><code>9bd3b44</code></a>
Improve readability of global.json creation command (<a
href="https://redirect.github.com/actions/setup-dotnet/issues/694">#694</a>)</li>
<li><a
href="https://github.com/actions/setup-dotnet/commit/4406a635cd2be9c92689ea22b2f74ea57297088c"><code>4406a63</code></a>
Bump <code>@​actions/cache</code> to 5.1.0, log cache write denied (<a
href="https://redirect.github.com/actions/setup-dotnet/issues/746">#746</a>)</li>
<li><a
href="https://github.com/actions/setup-dotnet/commit/dc3262dda80e97f1c7865b3b122e99240e30b738"><code>dc3262d</code></a>
pin actions to commit SHAs in workflows (<a
href="https://redirect.github.com/actions/setup-dotnet/issues/744">#744</a>)</li>
<li><a
href="https://github.com/actions/setup-dotnet/commit/95a3f8b067437dc9b2027a437f5dc3b4569ddd49"><code>95a3f8b</code></a>
Validate global.json SDK version before rollForward optimization (<a
href="https://redirect.github.com/actions/setup-dotnet/issues/742">#742</a>)</li>
<li>See full diff in <a
href="https://github.com/actions/setup-dotnet/compare/9a946fdbd5fb07b82b2f5a4466058b876ab72bb2...26b0ec14cb23fa6904739307f278c14f94c95bf1">compare
view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=actions/setup-dotnet&package-manager=github_actions&previous-version=5.3.0&new-version=5.4.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Ports the branch-scoped self-publishing CI/CD from
`ptr727/LanguageTags`, replacing the ProjectTemplate two-phase model.
`main` publishes stable releases and `develop` publishes prereleases;
each branch publishes itself when a shipped input changes. Utilities has
no codegen, so the generator workflows and merge-bot codegen job are
omitted.
## Workflows
- Remove `build-datebadge-task.yml`, `build-nugetlibrary-task.yml`,
`get-version-task.yml`.
- Add `validate-task.yml` (unit tests + CSharpier / `dotnet format
style` / markdownlint / cspell / actionlint).
- Rework `build-release-task.yml` (NBGV, keyless OIDC `NuGet/login`
push, flat `Utilities.7z` asset), `publish-release.yml` (push/dispatch
self-publisher with a shipped-input inclusion list),
`test-pull-request.yml` (validate + smoke-build + `Check pull request
workflow status job` aggregator), and `merge-bot-pull-request.yml`
(Dependabot auto-merge only).
## Config and docs
- Add `WORKFLOW.md` (canonical CI/CD spec, codegen sections removed) and
`repo-config/` (rulesets + settings as code, `delete_branch_on_merge`
off).
- Add `cspell.json` as the single spell-check source; reconcile
`AGENTS.md`, `CODESTYLE.md`, `.github/copilot-instructions.md`,
`.github/dependabot.yml`, `.vscode/tasks.json`, and `Utilities.slnx`.
- Bump version floor 3.5 -> 3.6; refresh `README.md` and `HISTORY.md`.
Verified locally: actionlint, markdownlint, cspell, YAML/JSON parse,
`bash -n configure.sh`, EOL per `.editorconfig`, and Husky
clean-compile.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 28, 2026 04:37

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Promotes the branch-scoped self-publishing CI/CD model (and related documentation/config-as-code) from develop to main, cutting the 3.6 stable release floor and aligning main with the new workflow contract.

Changes:

  • Introduce a reusable CI validation gate (validate-task.yml) and rework PR + publish workflows around branch-scoped, single-ref releases.
  • Add CI/CD specification and repo configuration-as-code (WORKFLOW.md, repo-config/) and refresh contributing/docs accordingly.
  • Bump the NBGV version floor to 3.6 and apply minor dependency/solution workspace updates.

Reviewed changes

Copilot reviewed 29 out of 29 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
WORKFLOW.mdAdds the canonical CI/CD workflow contract, architecture, and verification methodology.
version.jsonBumps NBGV version floor to 3.6 for the stable release line.
Utilities.slnxUpdates solution items/workflow references to match the new pipeline and docs.
Utilities.code-workspaceRemoves embedded CSpell dictionary in favor of a dedicated cspell.json.
repo-config/settings.jsonCodifies repo-level settings (merge methods, auto-merge, etc.).
repo-config/ruleset-main.jsonCodifies the main branch ruleset (merge-commit-only, required check, signatures).
repo-config/ruleset-develop.jsonCodifies the develop branch ruleset (squash-only/linear history, required check, signatures).
repo-config/README.mdDocuments how the configuration-as-code directory is applied and audited.
repo-config/configure.shAdds an idempotent gh api script to apply/check rulesets, settings, and required secrets.
README.mdUpdates distribution links, badges, and contributing guidance to reflect the new CI/CD model.
HISTORY.mdAdds v3.6 release notes describing the CI/CD and publishing changes.
Directory.Packages.propsUpdates Microsoft.NET.Test.Sdk to 18.7.0.
cspell.jsonAdds a repo-wide CSpell configuration and accepted word list.
CODESTYLE.mdUpdates code-style documentation to reflect current tooling and CI lint behavior.
AGENTS.mdRefactors agent guidance to point to WORKFLOW.md for CI/CD and clarifies review/merge gate expectations.
.vscode/tasks.jsonCleans up task file commentary and clarifies clean-compile vs convenience tasks.
.markdownlint-cli2.jsoncClarifies MD060 policy (table column style) in markdownlint configuration.
.github/workflows/validate-task.ymlAdds reusable validation workflow (unit tests + lint suite).
.github/workflows/test-pull-request.ymlSwitches PR gating to push-based CI for head-resolved workflow self-testing + required aggregator.
.github/workflows/publish-release.ymlReworks publishing to branch-scoped self-publishing on shipped-input changes or dispatch (no schedule).
.github/workflows/merge-bot-pull-request.ymlSimplifies merge-bot logic; enables auto-merge for Dependabot on both branches and disables on maintainer pushes.
.github/workflows/get-version-task.ymlRemoves standalone reusable version task (versioning now inlined into build-release-task).
.github/workflows/build-release-task.ymlConsolidates version/build/publish/release responsibilities; adds OIDC NuGet publishing and flat Utilities.7z asset.
.github/workflows/build-nugetlibrary-task.ymlRemoves legacy build task superseded by build-release-task.
.github/workflows/build-datebadge-task.ymlRemoves decorative date-badge workflow from the pipeline.
.github/dependabot.ymlTightens and shortens rationale comments while keeping dual-target updates.
.github/copilot-instructions.mdMinor wording updates in Copilot runbook and references.
.gitattributesClarifies EOL strategy and pins LF for execution-sensitive script classes.
.editorconfigRefines per-file-type EOL rules and adds ReSharper settings; adjusts C# analyzer settings.

Comment thread.editorconfig
Comment on lines 17 to 21
[*]
charset = utf-8
end_of_line = crlf
indent_size = 4
indent_style = space
insert_final_newline = true
Comment threadCODESTYLE.md
Comment on lines 198 to 202
1. **XML documentation**
- `<GenerateDocumentationFile>true</GenerateDocumentationFile>`
- Document all public surfaces.
- Missing XML comments for public APIs are suppressed (`.editorconfig`)
- Must document all public surfaces.
- Single-line summaries, additional details in remarks, document input parameters, return values, exceptions, and add crefs
@ptr727
ptr727 merged commit 1cbe6b2 into mainJun 28, 2026
17 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Promote develop to main: branch-scoped CI/CD + 3.6 - #350

Merged
ptr727 merged 4 commits into
mainfrom
develop
Jun 28, 2026
Merged

Promote develop to main: branch-scoped CI/CD + 3.6#350
ptr727 merged 4 commits into
mainfrom
develop

Conversation

@ptr727

Copy link
Copy Markdown
Owner

Promote the branch-scoped self-publishing CI/CD migration to main, cutting the 3.6 stable release.

Carries the develop work: 5-workflow self-publishing pipeline (no codegen), WORKFLOW.md, repo-config/ (rulesets + settings as code), keyless OIDC NuGet publishing, flat Utilities.7z release packaging, reconciled docs, and the 3.6 version floor. The 3.6 prerelease published from develop verified clean (flat archive, NuGet package + symbols pushed).

Merge method is a merge commit (not squash) so main keeps a real reference to develop's commits.

🤖 Generated with Claude Code

dependabotBotand others added 4 commits June 23, 2026 14:55
Updated [Microsoft.NET.Test.Sdk](https://github.com/microsoft/vstest)
from 18.6.0 to 18.7.0.
<details>
<summary>Release notes</summary>
_Sourced from [Microsoft.NET.Test.Sdk's
releases](https://github.com/microsoft/vstest/releases)._
## 18.7.0
## What's Changed
* Add ARM64 msdia140.dll support to test platform packages by
@​jamesmcroft in microsoft/vstest#15689
* Update System.Memory from 4.5.5 to 4.6.3 by @​nohwnd in
microsoft/vstest#15706
## New Contributors
* @​jamesmcroft made their first contribution in
microsoft/vstest#15689
**Full Changelog**:
microsoft/vstest@v18.6.0...v18.7.0
Commits viewable in [compare
view](microsoft/vstest@v18.6.0...v18.7.0).
</details>
[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=Microsoft.NET.Test.Sdk&package-manager=nuget&previous-version=18.6.0&new-version=18.7.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…ce (#344)
Re-syncs this repo's carried governance/config artifacts and CI
orchestration to the current
[ptr727/ProjectTemplate](https://github.com/ptr727/ProjectTemplate)
(template-convergence barrier), and folds in this repo's task list. Held
for maintainer end-gate review - do not auto-merge.
## What this does
- **Carried artifacts re-synced to the template** (adapting only the
sanctioned placeholders): `AGENTS.md` "PR Review Etiquette",
`.github/copilot-instructions.md`, `.markdownlint-cli2.jsonc`,
`.editorconfig`, `.gitattributes`, and `CODESTYLE.md`. The carried files
are byte-for-byte the template's except for the documented adaptations
below. Carried workflow YAML stays CRLF to match the template's
checked-in form (per `.editorconfig`).
- **`CODESTYLE.md` carried whole** (General + .NET + Python). Only the
.NET section is consumed here; the Python section is inert but kept so
re-sync stays a wholesale replace.
- **Orchestration workflows aligned with the template:**
- `build-release-task.yml` / `build-nugetlibrary-task.yml`:
`github-release` decoupled from the build job; the download collects by
`pattern: release-asset-${{ inputs.branch }}-*` + `merge-multiple: true`
with `fail_on_unmatched_files: true`; the NuGet upload is renamed to
`release-asset-<branch>-nugetlibrary` and the unused `artifact-id`
output dropped; adds the main-only prerelease-suffix backstop.
- `merge-bot-pull-request.yml`: concurrency keyed per-PR
(`github.event.pull_request.number`) so bot PRs against the same base
queue independently.
- `publish-release.yml`: dispatch-from-default-branch guard.
- `test-pull-request.yml`: terminal `cleanup-artifacts` job (`needs:
[smoke-build]`), independent of `check-workflow-status` so housekeeping
never gates the required merge check.
## Documented adaptations (for review)
These are the only intentional deviations from the template; everything
else matches it. Sourced from `AGENTS.md` "Template Adaptations".
- **NuGet-only target set.** No Docker, executable, PyPI, or codegen
targets, so the corresponding `build-*-task.yml` / `run-codegen-*.yml`
workflows are absent and the merge-bot carries only the Dependabot path.
`publish-release.yml` keeps its repo-specific per-branch `date-badge`
matrix and omits the template's PyPI/Docker jobs.
- **Husky-driven clean-compile as the CI style gate.** The template
lints style directly in CI; this repo wires Husky.Net as a local
pre-commit gate and runs the same CSharpier + `dotnet format` checks in
CI via `dotnet husky run`, so the local gate and CI run identical
commands. Sanctioned by `CODESTYLE.md` "Clean-Compile Verification".
- **`.husky/pre-commit` LF pin.** `.editorconfig` adds a
`[.husky/pre-commit]` LF block and `.gitattributes` adds
`.husky/pre-commit text eol=lf` (the template's `[*.sh]` / `*.sh` rules
do not match the extensionless hook). Required because this repo ships
the Husky hook.
- **Brownfield analyzer relaxations.** A pre-existing set of analyzer
rules is relaxed to suggestion in `.editorconfig` (and `IL3058` via
`NoWarn`) to keep the published public API stable; each is documented
inline.
Validation: actionlint clean, markdownlint 0 errors, carried-config
diffs vs the template are EOL/adaptation-only.
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…up (#346)
Bumps the actions-deps group with 1 update:
[actions/setup-dotnet](https://github.com/actions/setup-dotnet).
Updates `actions/setup-dotnet` from 5.3.0 to 5.4.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/actions/setup-dotnet/releases">actions/setup-dotnet's
releases</a>.</em></p>
<blockquote>
<h2>v5.4.0</h2>
<h2>What's Changed</h2>
<h3>Enhancements</h3>
<ul>
<li>Improve global.json SDK version validation for rollForward by <a
href="https://github.com/priyagupta108"><code>@​priyagupta108</code></a>
in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/742">actions/setup-dotnet#742</a></li>
<li>Pin actions to commit SHAs in workflows by <a
href="https://github.com/priya-kinthali"><code>@​priya-kinthali</code></a>
in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/744">actions/setup-dotnet#744</a></li>
<li>Expand the CSC problem matcher to light up more errors on GitHub. by
<a
href="https://github.com/StephenCleary"><code>@​StephenCleary</code></a>
in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/717">actions/setup-dotnet#717</a></li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Docs(action): Explicitly mark all optional inputs with required:
false by <a
href="https://github.com/kranthipoturaju"><code>@​kranthipoturaju</code></a>
in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/737">actions/setup-dotnet#737</a></li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li>Fix global.json creation command by <a
href="https://github.com/michal2612"><code>@​michal2612</code></a> in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/694">actions/setup-dotnet#694</a></li>
</ul>
<h3>Dependency Updates</h3>
<ul>
<li>Upgrade <code>@​actions/cache</code> to 5.1.0, log cache write
denied by <a
href="https://github.com/jasongin"><code>@​jasongin</code></a> in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/746">actions/setup-dotnet#746</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/jasongin"><code>@​jasongin</code></a>
made their first contribution in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/746">actions/setup-dotnet#746</a></li>
<li><a
href="https://github.com/michal2612"><code>@​michal2612</code></a> made
their first contribution in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/694">actions/setup-dotnet#694</a></li>
<li><a
href="https://github.com/kranthipoturaju"><code>@​kranthipoturaju</code></a>
made their first contribution in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/737">actions/setup-dotnet#737</a></li>
<li><a
href="https://github.com/StephenCleary"><code>@​StephenCleary</code></a>
made their first contribution in <a
href="https://redirect.github.com/actions/setup-dotnet/pull/717">actions/setup-dotnet#717</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/setup-dotnet/compare/v5...v5.4.0">https://github.com/actions/setup-dotnet/compare/v5...v5.4.0</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/actions/setup-dotnet/commit/26b0ec14cb23fa6904739307f278c14f94c95bf1"><code>26b0ec1</code></a>
Expand the CSC problem matcher to light up more errors on GitHub. (<a
href="https://redirect.github.com/actions/setup-dotnet/issues/717">#717</a>)</li>
<li><a
href="https://github.com/actions/setup-dotnet/commit/da5e5482f2d0700168cff080da45b50da8b60f0e"><code>da5e548</code></a>
docs(action): explicitly mark all optional inputs with required: false
(<a
href="https://redirect.github.com/actions/setup-dotnet/issues/737">#737</a>)</li>
<li><a
href="https://github.com/actions/setup-dotnet/commit/9bd3b44355ba7c500f3d2e029636c6d29ac5caab"><code>9bd3b44</code></a>
Improve readability of global.json creation command (<a
href="https://redirect.github.com/actions/setup-dotnet/issues/694">#694</a>)</li>
<li><a
href="https://github.com/actions/setup-dotnet/commit/4406a635cd2be9c92689ea22b2f74ea57297088c"><code>4406a63</code></a>
Bump <code>@​actions/cache</code> to 5.1.0, log cache write denied (<a
href="https://redirect.github.com/actions/setup-dotnet/issues/746">#746</a>)</li>
<li><a
href="https://github.com/actions/setup-dotnet/commit/dc3262dda80e97f1c7865b3b122e99240e30b738"><code>dc3262d</code></a>
pin actions to commit SHAs in workflows (<a
href="https://redirect.github.com/actions/setup-dotnet/issues/744">#744</a>)</li>
<li><a
href="https://github.com/actions/setup-dotnet/commit/95a3f8b067437dc9b2027a437f5dc3b4569ddd49"><code>95a3f8b</code></a>
Validate global.json SDK version before rollForward optimization (<a
href="https://redirect.github.com/actions/setup-dotnet/issues/742">#742</a>)</li>
<li>See full diff in <a
href="https://github.com/actions/setup-dotnet/compare/9a946fdbd5fb07b82b2f5a4466058b876ab72bb2...26b0ec14cb23fa6904739307f278c14f94c95bf1">compare
view</a></li>
</ul>
</details>
<br />
[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=actions/setup-dotnet&package-manager=github_actions&previous-version=5.3.0&new-version=5.4.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Ports the branch-scoped self-publishing CI/CD from
`ptr727/LanguageTags`, replacing the ProjectTemplate two-phase model.
`main` publishes stable releases and `develop` publishes prereleases;
each branch publishes itself when a shipped input changes. Utilities has
no codegen, so the generator workflows and merge-bot codegen job are
omitted.
## Workflows
- Remove `build-datebadge-task.yml`, `build-nugetlibrary-task.yml`,
`get-version-task.yml`.
- Add `validate-task.yml` (unit tests + CSharpier / `dotnet format
style` / markdownlint / cspell / actionlint).
- Rework `build-release-task.yml` (NBGV, keyless OIDC `NuGet/login`
push, flat `Utilities.7z` asset), `publish-release.yml` (push/dispatch
self-publisher with a shipped-input inclusion list),
`test-pull-request.yml` (validate + smoke-build + `Check pull request
workflow status job` aggregator), and `merge-bot-pull-request.yml`
(Dependabot auto-merge only).
## Config and docs
- Add `WORKFLOW.md` (canonical CI/CD spec, codegen sections removed) and
`repo-config/` (rulesets + settings as code, `delete_branch_on_merge`
off).
- Add `cspell.json` as the single spell-check source; reconcile
`AGENTS.md`, `CODESTYLE.md`, `.github/copilot-instructions.md`,
`.github/dependabot.yml`, `.vscode/tasks.json`, and `Utilities.slnx`.
- Bump version floor 3.5 -> 3.6; refresh `README.md` and `HISTORY.md`.
Verified locally: actionlint, markdownlint, cspell, YAML/JSON parse,
`bash -n configure.sh`, EOL per `.editorconfig`, and Husky
clean-compile.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CopilotAI review requested due to automatic review settings June 28, 2026 04:37

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Promotes the branch-scoped self-publishing CI/CD model (and related documentation/config-as-code) from develop to main, cutting the 3.6 stable release floor and aligning main with the new workflow contract.

Changes:

  • Introduce a reusable CI validation gate (validate-task.yml) and rework PR + publish workflows around branch-scoped, single-ref releases.
  • Add CI/CD specification and repo configuration-as-code (WORKFLOW.md, repo-config/) and refresh contributing/docs accordingly.
  • Bump the NBGV version floor to 3.6 and apply minor dependency/solution workspace updates.

Reviewed changes

Copilot reviewed 29 out of 29 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
WORKFLOW.mdAdds the canonical CI/CD workflow contract, architecture, and verification methodology.
version.jsonBumps NBGV version floor to 3.6 for the stable release line.
Utilities.slnxUpdates solution items/workflow references to match the new pipeline and docs.
Utilities.code-workspaceRemoves embedded CSpell dictionary in favor of a dedicated cspell.json.
repo-config/settings.jsonCodifies repo-level settings (merge methods, auto-merge, etc.).
repo-config/ruleset-main.jsonCodifies the main branch ruleset (merge-commit-only, required check, signatures).
repo-config/ruleset-develop.jsonCodifies the develop branch ruleset (squash-only/linear history, required check, signatures).
repo-config/README.mdDocuments how the configuration-as-code directory is applied and audited.
repo-config/configure.shAdds an idempotent gh api script to apply/check rulesets, settings, and required secrets.
README.mdUpdates distribution links, badges, and contributing guidance to reflect the new CI/CD model.
HISTORY.mdAdds v3.6 release notes describing the CI/CD and publishing changes.
Directory.Packages.propsUpdates Microsoft.NET.Test.Sdk to 18.7.0.
cspell.jsonAdds a repo-wide CSpell configuration and accepted word list.
CODESTYLE.mdUpdates code-style documentation to reflect current tooling and CI lint behavior.
AGENTS.mdRefactors agent guidance to point to WORKFLOW.md for CI/CD and clarifies review/merge gate expectations.
.vscode/tasks.jsonCleans up task file commentary and clarifies clean-compile vs convenience tasks.
.markdownlint-cli2.jsoncClarifies MD060 policy (table column style) in markdownlint configuration.
.github/workflows/validate-task.ymlAdds reusable validation workflow (unit tests + lint suite).
.github/workflows/test-pull-request.ymlSwitches PR gating to push-based CI for head-resolved workflow self-testing + required aggregator.
.github/workflows/publish-release.ymlReworks publishing to branch-scoped self-publishing on shipped-input changes or dispatch (no schedule).
.github/workflows/merge-bot-pull-request.ymlSimplifies merge-bot logic; enables auto-merge for Dependabot on both branches and disables on maintainer pushes.
.github/workflows/get-version-task.ymlRemoves standalone reusable version task (versioning now inlined into build-release-task).
.github/workflows/build-release-task.ymlConsolidates version/build/publish/release responsibilities; adds OIDC NuGet publishing and flat Utilities.7z asset.
.github/workflows/build-nugetlibrary-task.ymlRemoves legacy build task superseded by build-release-task.
.github/workflows/build-datebadge-task.ymlRemoves decorative date-badge workflow from the pipeline.
.github/dependabot.ymlTightens and shortens rationale comments while keeping dual-target updates.
.github/copilot-instructions.mdMinor wording updates in Copilot runbook and references.
.gitattributesClarifies EOL strategy and pins LF for execution-sensitive script classes.
.editorconfigRefines per-file-type EOL rules and adds ReSharper settings; adjusts C# analyzer settings.

Comment thread.editorconfig
Comment on lines 17 to 21
[*]
charset = utf-8
end_of_line = crlf
indent_size = 4
indent_style = space
insert_final_newline = true
Comment threadCODESTYLE.md
Comment on lines 198 to 202
1. **XML documentation**
- `<GenerateDocumentationFile>true</GenerateDocumentationFile>`
- Document all public surfaces.
- Missing XML comments for public APIs are suppressed (`.editorconfig`)
- Must document all public surfaces.
- Single-line summaries, additional details in remarks, document input parameters, return values, exceptions, and add crefs
@ptr727
ptr727 merged commit 1cbe6b2 into mainJun 28, 2026
17 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ptr727