Revert to branch-scoped self-publishing CI/CD - #204
Merged
Conversation
Replace the shared project-template workflow model with a branch-scoped, self-sufficient set written for this repo. One run targets the branch it was triggered on; NBGV versions it natively (no IGNORE_GITHUB_REF / checkout -B); a reusable validate-task (unit tests + lint) gates both the pull request and the publisher; and a shipped-input push to main/develop self-publishes (main stable, develop prerelease) with no schedule or PUBLISH_ON_MERGE. - Add WORKFLOW.md: canonical branch-scoped CI/CD spec plus audit methodology. - Add validate-task.yml (unit-test plus lint: csharpier, dotnet format, markdownlint, cspell, actionlint); PR gate and publish job both need it. - Rewrite publish-release/test-pull-request/build-release-task; delete the get-version/build-nugetlibrary/build-datebadge tasks. - NuGet publishing is keyless via OIDC trusted publishing (NUGET_USERNAME, no long-lived API key). - Add repo-config/ (rulesets, settings, configure.sh apply|check 5D audit) and cspell.json (single-source spell dictionary). - Reconcile AGENTS.md/CODESTYLE.md/README.md/HISTORY.md; bump version to 1.5. Rename the required status check to "Check pull request workflow status job"; the live ruleset must be applied in lockstep (repo-config/configure.sh apply). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Contributor
There was a problem hiding this comment.
Pull request overview
This PR replaces the template-derived, matrix/scheduled CI/CD with a repo-specific, branch-scoped workflow set where each run targets only the triggering branch (main = stable, develop = prerelease), reusing a single validate-task gate for both PR validation and publishing. It also codifies repo settings/rulesets/secrets-as-names under repo-config/ and updates docs/versioning to reflect the new operational contract.
Changes:
- Added a canonical CI/CD contract + audit methodology (
WORKFLOW.md) and a config-as-code audit/apply toolchain (repo-config/). - Introduced
validate-task.yml(unit test + lint suite) and rewiredtest-pull-request.yml/publish-release.yml/build-release-task.ymlaround branch-scoped self-publishing + OIDC NuGet trusted publishing. - Updated release/docs metadata (bump
version.jsonto 1.5; refreshedREADME.md,HISTORY.md,AGENTS.md,CODESTYLE.md; centralized spelling words incspell.jsonand removed workspace-local dictionary).
Reviewed changes
Copilot reviewed 23 out of 23 changed files in this pull request and generated 5 comments.
Show a summary per file
| File | Description |
|---|---|
| WORKFLOW.md | New end-to-end CI/CD contract (architecture, guarantees, and audit methodology). |
| version.json | Bumps version floor from 1.4 to 1.5. |
| repo-config/settings.json | Declares desired repository settings (auto-merge, merge methods, delete-branch-on-merge). |
| repo-config/ruleset-main.json | Codifies main ruleset (merge-commit only, required check, signatures, strict off). |
| repo-config/ruleset-develop.json | Codifies develop ruleset (squash-only + linear history, required check, signatures, strict off). |
| repo-config/README.md | Documents config-as-code scope and the required-check rename lockstep. |
| repo-config/configure.sh | Adds `apply |
| README.md | Updates release notes, CI/CD description, required-check name, and publishing/auth model. |
| HISTORY.md | Adds 1.5 entry describing CI/CD revert/rework and keyless publishing. |
| LanguageTags.code-workspace | Removes embedded cSpell word list (now centralized in cspell.json). |
| cspell.json | New single-source spell dictionary + ignore paths. |
| CODESTYLE.md | Updates clean-compile/lint/spell guidance to match CI + cspell.json. |
| AGENTS.md | Re-points CI/CD canon to WORKFLOW.md and updates merge/release semantics accordingly. |
| .github/workflows/validate-task.yml | New reusable validation gate (unit tests + CSharpier/dotnet-format/markdownlint/cspell/actionlint). |
| .github/workflows/test-pull-request.yml | Reworked CI entry workflow to run on push + produce the ruleset-bound aggregator check. |
| .github/workflows/publish-release.yml | Reworked publisher to be branch-scoped + shipped-input path gated; uses validate-task gate. |
| .github/workflows/build-release-task.yml | Reworked build/version/publish/release reusable task; adds OIDC NuGet trusted publishing and simplified asset handling. |
| .github/workflows/run-periodic-codegen-pull-request.yml | Updates description/comments; maintains scheduled daily codegen entry workflow. |
| .github/workflows/run-codegen-pull-request-task.yml | Updates documentation/comments around per-branch codegen PR creation. |
| .github/workflows/merge-bot-pull-request.yml | Removes semver-major NuGet exception; makes Dependabot auto-merge unconditional on green checks. |
| .github/workflows/get-version-task.yml | Deleted (versioning now handled inside build-release-task.yml). |
| .github/workflows/build-nugetlibrary-task.yml | Deleted (logic folded into build-release-task.yml). |
| .github/workflows/build-datebadge-task.yml | Deleted (BYOB date badge removed). |
The project sets GeneratePackageOnBuild, so the build emits the .nupkg
(+ .snupkg). Running dotnet pack on top of that double-packs and fails to
find the assembly under the .artifacts layout ("LanguageTags.dll to be
packed was not found"). Build instead, redirecting OutputPath and
PackageOutputPath out of .artifacts, matching the prior working task.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…ctionlint - WORKFLOW.md: frame dependency-bump exclusion as a deliberate churn-avoidance policy, not a "no compiled code change" technical invariant (x2). - build-release-task: correct the smoke validate-release skip rationale; smoke can run on main, so the reason is "smoke never publishes", not "never main". - validate-task: verify the actionlint release tarball against its published SHA-256 before extracting/executing it, closing the unchecked-download path. - test-pull-request: make the no-pull_request-trigger fork constraint and the maintainer workflow explicit in the header. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
… action - Replace Unicode arrows (->) and an ellipsis (...) in README.md and the dependabot.yml comments with ASCII, per AGENTS.md "no Unicode arrows / no ellipsis character". - Lint workflows via the SHA-pinned raven-actions/actionlint action (vendors actionlint + shellcheck) instead of a hand-rolled curl download, matching the repo's pin-every-action convention and dropping manual checksum upkeep. The snupkg comment is a false positive: dotnet nuget push auto-pushes the co-located .snupkg to nuget.org (no --no-symbols), as the workflow documents. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Comments: - Trim verbose workflow comments to the non-obvious points. Move the snupkg note onto the push step, name GitCommitId where comments said "built commit", and make the artifact-delete gate explicit. - Restructure publish-release's top comment into bullets, and drop prose semicolons and inline spec-section refs (D4.6 etc.) across the workflows. - Reflow dependabot.yml comments to ~120-column structured lines. - AGENTS.md comments rule now prefers structure over a long prose paragraph. Scope docs to C# and Actions, dropping shared-template carryover: - Remove the Python section and the multi-language / derived-repo framing from CODESTYLE.md; de-template .editorconfig, copilot-instructions.md, and .vscode/tasks.json. - Prune orphaned Python-tooling words from cspell.json. tasks.json: add "Run Codegen" and "Codegen and Format" (codegen then CSharpier, since generated line lengths are not always CSharpier-aligned). README contributing/setup now point to WORKFLOW.md, CODESTYLE.md, and repo-config (maintainer edit). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
- Reconcile the Dependabot/fork validation contract: there is no pull_request trigger, so Dependabot PRs (in-repo branches) validate via their push, and only forks (which cannot push) need maintainer action. Previously the doc claimed a base-resolved pull_request fallback that does not exist. - cspell: set language to en-US to match the documented US-English rule. - Remove the temporary go-live adoption note. - Drop the project-type generality section and the multi-shape / portability framing, scoping the spec to this NuGet library's workflows. - Fix a broken concurrency sentence and clause-joining semicolons. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
check_secrets now passes --paginate to the actions/secrets and dependabot/secrets endpoints, so a repo with more than 30 secrets cannot miss a required name and report a false failure. The NuGet/login output finding is a false positive: the pinned NuGet/login@v1.2.0 action.yml outputs NUGET_API_KEY, which the push step uses. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Tighten the verbose narrative in sections 0 and 3 and the longest guarantees (D4.6, D8.3), drop redundant re-explanation, and remove clause-joining semicolons. All guarantees (D0-D10) and scenarios (S1-S15) are preserved. Also fix a model-paragraph inconsistency: it listed a runtime-dependency update as auto-publishing, but dependency bumps are excluded from the shipped-input inclusion list. The package publishes on a shipped-input change. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
- test-pull-request: restrict the push trigger to branches ['**'] so release tags never re-run CI (the contract is CI for every branch, not tags). - configure.sh and repo-config README: both check and apply use admin-only rulesets/secrets endpoints, so check needs an admin-authenticated gh token too (read-only, but not the default CI token). Corrected the misleading "safe for CI" wording. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This was referenced Jun 29, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Replaces the shared project-template CI/CD with a branch-scoped, self-sufficient workflow set written for this repo. One run targets the branch it was triggered on; NBGV versions it natively; a reusable
validate-task(unit tests + lint) gates both the pull request and the publisher; and a shipped-input push tomain/developself-publishes (mainstable,developprerelease) with no schedule orPUBLISH_ON_MERGE.Changes
WORKFLOW.md- canonical branch-scoped CI/CD spec + audit methodology (5A static / 5B trace / 5C live / 5D config).validate-task.yml- unit-test + lint (csharpier, dotnet format, markdownlint, cspell, actionlint); the PR gate and the publish job bothneed:it, so nothing publishes that would fail the PR.publish-release/test-pull-request/build-release-task; deletedget-version/build-nugetlibrary/build-datebadge.NUGET_USERNAME, no API key).repo-config/- rulesets, settings, andconfigure.sh apply|check(the 5D config audit).cspell.json- single-source spell dictionary (extension + CLI + CI read it).AGENTS.md/CODESTYLE.md/README.md/HISTORY.md; bumped to 1.5.Go-live coordination (maintainer)
Check pull request workflow status job. The live ruleset still requires the old name, sorepo-config/configure.sh applymust run in lockstep with merging this PR (it also fixesdelete_branch_on_merge). Until then the live required check is satisfied by the base-resolved old workflow.version.jsonis bumped (1.4 -> 1.5), a shipped input, so merging this todevelopwill auto-publish a1.5prerelease to NuGet. Intended, but flagging it.🤖 Generated with Claude Code