Skip to content

Revert to branch-scoped self-publishing CI/CD - #204

Merged
ptr727 merged 9 commits into
developfrom
feature/branch-scoped-cicd
Jun 28, 2026
Merged

Revert to branch-scoped self-publishing CI/CD#204
ptr727 merged 9 commits into
developfrom
feature/branch-scoped-cicd

Conversation

@ptr727

@ptr727 ptr727 commented Jun 27, 2026

Copy link
Copy Markdown
Owner

Summary

Replaces the shared project-template CI/CD with a branch-scoped, self-sufficient workflow set written for this repo. One run targets the branch it was triggered on; NBGV versions it natively; a reusable validate-task (unit tests + lint) gates both the pull request and the publisher; and a shipped-input push to main/develop self-publishes (main stable, develop prerelease) with no schedule or PUBLISH_ON_MERGE.

Changes

  • WORKFLOW.md - canonical branch-scoped CI/CD spec + audit methodology (5A static / 5B trace / 5C live / 5D config).
  • validate-task.yml - unit-test + lint (csharpier, dotnet format, markdownlint, cspell, actionlint); the PR gate and the publish job both need: it, so nothing publishes that would fail the PR.
  • Rewrote publish-release / test-pull-request / build-release-task; deleted get-version / build-nugetlibrary / build-datebadge.
  • NuGet publishing is keyless via OIDC trusted publishing (NUGET_USERNAME, no API key).
  • repo-config/ - rulesets, settings, and configure.sh apply|check (the 5D config audit).
  • cspell.json - single-source spell dictionary (extension + CLI + CI read it).
  • Reconciled AGENTS.md / CODESTYLE.md / README.md / HISTORY.md; bumped to 1.5.

Go-live coordination (maintainer)

  • The aggregator required check is renamed to Check pull request workflow status job. The live ruleset still requires the old name, so repo-config/configure.sh apply must run in lockstep with merging this PR (it also fixes delete_branch_on_merge). Until then the live required check is satisfied by the base-resolved old workflow.
  • version.json is bumped (1.4 -> 1.5), a shipped input, so merging this to develop will auto-publish a 1.5 prerelease to NuGet. Intended, but flagging it.

🤖 Generated with Claude Code

Replace the shared project-template workflow model with a branch-scoped,
self-sufficient set written for this repo. One run targets the branch it was
triggered on; NBGV versions it natively (no IGNORE_GITHUB_REF / checkout -B);
a reusable validate-task (unit tests + lint) gates both the pull request and
the publisher; and a shipped-input push to main/develop self-publishes (main
stable, develop prerelease) with no schedule or PUBLISH_ON_MERGE.

- Add WORKFLOW.md: canonical branch-scoped CI/CD spec plus audit methodology.
- Add validate-task.yml (unit-test plus lint: csharpier, dotnet format,
  markdownlint, cspell, actionlint); PR gate and publish job both need it.
- Rewrite publish-release/test-pull-request/build-release-task; delete the
  get-version/build-nugetlibrary/build-datebadge tasks.
- NuGet publishing is keyless via OIDC trusted publishing (NUGET_USERNAME, no
  long-lived API key).
- Add repo-config/ (rulesets, settings, configure.sh apply|check 5D audit) and
  cspell.json (single-source spell dictionary).
- Reconcile AGENTS.md/CODESTYLE.md/README.md/HISTORY.md; bump version to 1.5.

Rename the required status check to "Check pull request workflow status job";
the live ruleset must be applied in lockstep (repo-config/configure.sh apply).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings June 27, 2026 21:21

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR replaces the template-derived, matrix/scheduled CI/CD with a repo-specific, branch-scoped workflow set where each run targets only the triggering branch (main = stable, develop = prerelease), reusing a single validate-task gate for both PR validation and publishing. It also codifies repo settings/rulesets/secrets-as-names under repo-config/ and updates docs/versioning to reflect the new operational contract.

Changes:

  • Added a canonical CI/CD contract + audit methodology (WORKFLOW.md) and a config-as-code audit/apply toolchain (repo-config/).
  • Introduced validate-task.yml (unit test + lint suite) and rewired test-pull-request.yml / publish-release.yml / build-release-task.yml around branch-scoped self-publishing + OIDC NuGet trusted publishing.
  • Updated release/docs metadata (bump version.json to 1.5; refreshed README.md, HISTORY.md, AGENTS.md, CODESTYLE.md; centralized spelling words in cspell.json and removed workspace-local dictionary).

Reviewed changes

Copilot reviewed 23 out of 23 changed files in this pull request and generated 5 comments.

Show a summary per file
File Description
WORKFLOW.md New end-to-end CI/CD contract (architecture, guarantees, and audit methodology).
version.json Bumps version floor from 1.4 to 1.5.
repo-config/settings.json Declares desired repository settings (auto-merge, merge methods, delete-branch-on-merge).
repo-config/ruleset-main.json Codifies main ruleset (merge-commit only, required check, signatures, strict off).
repo-config/ruleset-develop.json Codifies develop ruleset (squash-only + linear history, required check, signatures, strict off).
repo-config/README.md Documents config-as-code scope and the required-check rename lockstep.
repo-config/configure.sh Adds `apply
README.md Updates release notes, CI/CD description, required-check name, and publishing/auth model.
HISTORY.md Adds 1.5 entry describing CI/CD revert/rework and keyless publishing.
LanguageTags.code-workspace Removes embedded cSpell word list (now centralized in cspell.json).
cspell.json New single-source spell dictionary + ignore paths.
CODESTYLE.md Updates clean-compile/lint/spell guidance to match CI + cspell.json.
AGENTS.md Re-points CI/CD canon to WORKFLOW.md and updates merge/release semantics accordingly.
.github/workflows/validate-task.yml New reusable validation gate (unit tests + CSharpier/dotnet-format/markdownlint/cspell/actionlint).
.github/workflows/test-pull-request.yml Reworked CI entry workflow to run on push + produce the ruleset-bound aggregator check.
.github/workflows/publish-release.yml Reworked publisher to be branch-scoped + shipped-input path gated; uses validate-task gate.
.github/workflows/build-release-task.yml Reworked build/version/publish/release reusable task; adds OIDC NuGet trusted publishing and simplified asset handling.
.github/workflows/run-periodic-codegen-pull-request.yml Updates description/comments; maintains scheduled daily codegen entry workflow.
.github/workflows/run-codegen-pull-request-task.yml Updates documentation/comments around per-branch codegen PR creation.
.github/workflows/merge-bot-pull-request.yml Removes semver-major NuGet exception; makes Dependabot auto-merge unconditional on green checks.
.github/workflows/get-version-task.yml Deleted (versioning now handled inside build-release-task.yml).
.github/workflows/build-nugetlibrary-task.yml Deleted (logic folded into build-release-task.yml).
.github/workflows/build-datebadge-task.yml Deleted (BYOB date badge removed).

Comment thread WORKFLOW.md Outdated
Comment thread WORKFLOW.md Outdated
Comment thread .github/workflows/build-release-task.yml Outdated
Comment thread .github/workflows/validate-task.yml Outdated
Comment thread .github/workflows/test-pull-request.yml Outdated
ptr727 and others added 2 commits June 27, 2026 14:26
The project sets GeneratePackageOnBuild, so the build emits the .nupkg
(+ .snupkg). Running dotnet pack on top of that double-packs and fails to
find the assembly under the .artifacts layout ("LanguageTags.dll to be
packed was not found"). Build instead, redirecting OutputPath and
PackageOutputPath out of .artifacts, matching the prior working task.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…ctionlint

- WORKFLOW.md: frame dependency-bump exclusion as a deliberate churn-avoidance
  policy, not a "no compiled code change" technical invariant (x2).
- build-release-task: correct the smoke validate-release skip rationale; smoke
  can run on main, so the reason is "smoke never publishes", not "never main".
- validate-task: verify the actionlint release tarball against its published
  SHA-256 before extracting/executing it, closing the unchecked-download path.
- test-pull-request: make the no-pull_request-trigger fork constraint and the
  maintainer workflow explicit in the header.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings June 27, 2026 21:31

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 23 out of 23 changed files in this pull request and generated 2 comments.

Comment thread .github/workflows/build-release-task.yml
Comment thread README.md Outdated
ptr727 and others added 2 commits June 27, 2026 14:39
… action

- Replace Unicode arrows (->) and an ellipsis (...) in README.md and the
  dependabot.yml comments with ASCII, per AGENTS.md "no Unicode arrows / no
  ellipsis character".
- Lint workflows via the SHA-pinned raven-actions/actionlint action (vendors
  actionlint + shellcheck) instead of a hand-rolled curl download, matching
  the repo's pin-every-action convention and dropping manual checksum upkeep.

The snupkg comment is a false positive: dotnet nuget push auto-pushes the
co-located .snupkg to nuget.org (no --no-symbols), as the workflow documents.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Comments:
- Trim verbose workflow comments to the non-obvious points. Move the snupkg
  note onto the push step, name GitCommitId where comments said "built
  commit", and make the artifact-delete gate explicit.
- Restructure publish-release's top comment into bullets, and drop prose
  semicolons and inline spec-section refs (D4.6 etc.) across the workflows.
- Reflow dependabot.yml comments to ~120-column structured lines.
- AGENTS.md comments rule now prefers structure over a long prose paragraph.

Scope docs to C# and Actions, dropping shared-template carryover:
- Remove the Python section and the multi-language / derived-repo framing
  from CODESTYLE.md; de-template .editorconfig, copilot-instructions.md, and
  .vscode/tasks.json.
- Prune orphaned Python-tooling words from cspell.json.

tasks.json: add "Run Codegen" and "Codegen and Format" (codegen then
CSharpier, since generated line lengths are not always CSharpier-aligned).

README contributing/setup now point to WORKFLOW.md, CODESTYLE.md, and
repo-config (maintainer edit).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings June 27, 2026 22:57

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 27 out of 27 changed files in this pull request and generated 2 comments.

Comment thread WORKFLOW.md Outdated
Comment thread cspell.json Outdated
- Reconcile the Dependabot/fork validation contract: there is no pull_request
  trigger, so Dependabot PRs (in-repo branches) validate via their push, and
  only forks (which cannot push) need maintainer action. Previously the doc
  claimed a base-resolved pull_request fallback that does not exist.
- cspell: set language to en-US to match the documented US-English rule.
- Remove the temporary go-live adoption note.
- Drop the project-type generality section and the multi-shape / portability
  framing, scoping the spec to this NuGet library's workflows.
- Fix a broken concurrency sentence and clause-joining semicolons.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 27 out of 27 changed files in this pull request and generated 2 comments.

Comment thread .github/workflows/build-release-task.yml
Comment thread repo-config/configure.sh
ptr727 and others added 2 commits June 27, 2026 16:19
check_secrets now passes --paginate to the actions/secrets and
dependabot/secrets endpoints, so a repo with more than 30 secrets cannot miss
a required name and report a false failure.

The NuGet/login output finding is a false positive: the pinned
NuGet/login@v1.2.0 action.yml outputs NUGET_API_KEY, which the push step uses.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Tighten the verbose narrative in sections 0 and 3 and the longest guarantees
(D4.6, D8.3), drop redundant re-explanation, and remove clause-joining
semicolons. All guarantees (D0-D10) and scenarios (S1-S15) are preserved.

Also fix a model-paragraph inconsistency: it listed a runtime-dependency
update as auto-publishing, but dependency bumps are excluded from the
shipped-input inclusion list. The package publishes on a shipped-input change.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings June 27, 2026 23:28

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 27 out of 27 changed files in this pull request and generated 4 comments.

Comment thread .github/workflows/test-pull-request.yml
Comment thread repo-config/configure.sh Outdated
Comment thread repo-config/README.md
Comment thread repo-config/README.md Outdated
- test-pull-request: restrict the push trigger to branches ['**'] so release
  tags never re-run CI (the contract is CI for every branch, not tags).
- configure.sh and repo-config README: both check and apply use admin-only
  rulesets/secrets endpoints, so check needs an admin-authenticated gh token
  too (read-only, but not the default CI token). Corrected the misleading
  "safe for CI" wording.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@ptr727
ptr727 merged commit b945a2b into develop Jun 28, 2026
10 checks passed
@ptr727
ptr727 deleted the feature/branch-scoped-cicd branch June 28, 2026 00:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants