Conversation
## Summary Replaces the shared project-template CI/CD with a branch-scoped, self-sufficient workflow set written for this repo. One run targets the branch it was triggered on; NBGV versions it natively; a reusable `validate-task` (unit tests + lint) gates both the pull request and the publisher; and a shipped-input push to `main`/`develop` self-publishes (`main` stable, `develop` prerelease) with no schedule or `PUBLISH_ON_MERGE`. ## Changes - **`WORKFLOW.md`** - canonical branch-scoped CI/CD spec + audit methodology (5A static / 5B trace / 5C live / 5D config). - **`validate-task.yml`** - unit-test + lint (csharpier, dotnet format, markdownlint, cspell, actionlint); the PR gate and the publish job both `need:` it, so nothing publishes that would fail the PR. - Rewrote `publish-release` / `test-pull-request` / `build-release-task`; deleted `get-version` / `build-nugetlibrary` / `build-datebadge`. - NuGet publishing is **keyless** via OIDC trusted publishing (`NUGET_USERNAME`, no API key). - **`repo-config/`** - rulesets, settings, and `configure.sh apply|check` (the 5D config audit). - **`cspell.json`** - single-source spell dictionary (extension + CLI + CI read it). - Reconciled `AGENTS.md` / `CODESTYLE.md` / `README.md` / `HISTORY.md`; bumped to **1.5**. ## Go-live coordination (maintainer) - The aggregator required check is renamed to **`Check pull request workflow status job`**. The live ruleset still requires the old name, so `repo-config/configure.sh apply` must run **in lockstep** with merging this PR (it also fixes `delete_branch_on_merge`). Until then the live required check is satisfied by the base-resolved old workflow. - `version.json` is bumped (1.4 -> 1.5), a shipped input, so **merging this to `develop` will auto-publish a `1.5` prerelease** to NuGet. Intended, but flagging it. 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
The OIDC token is requested by `NuGet/login` inside the reusable `build-release-task.yml`, so its `job_workflow_ref` names that file, not the `publish-release.yml` entry workflow. The NuGet.org trusted-publishing policy must name `build-release-task.yml`. Found by the first real publish (1.5 prerelease on develop): `Token exchange failed (HTTP 401) ... Workflow mismatch for policy 'LanguageTags': expected 'publish-release.yml', actual 'build-release-task.yml'`. Policy already repointed to `build-release-task.yml`; this corrects WORKFLOW.md D4.7 / section 6 and `configure.sh` to match. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Contributor
There was a problem hiding this comment.
Pull request overview
Promotes develop to main for the 1.5 stable release by switching to the branch-scoped, self-publishing CI/CD model (with a documented workflow contract) and codifying required GitHub repository settings/rulesets as code.
Changes:
- Introduce a new CI/CD contract and verification methodology (
WORKFLOW.md) and align contributor docs to it. - Replace the prior multi-workflow release pipeline with branch-scoped validation + build/publish reusable tasks, including OIDC trusted NuGet publishing.
- Add
repo-config/configuration-as-code (rulesets, settings, drift-check/apply script) and centralize spelling configuration incspell.json.
Reviewed changes
Copilot reviewed 27 out of 27 changed files in this pull request and generated 3 comments.
Show a summary per file
| File | Description |
|---|---|
| WORKFLOW.md | New canonical CI/CD contract, architecture, and audit methodology. |
| version.json | Bump version floor from 1.4 to 1.5 for the 1.5 release line. |
| repo-config/settings.json | Codify repository merge/auto-merge settings for drift auditing. |
| repo-config/ruleset-main.json | Codify main branch ruleset (merge-only, required checks, signatures, Copilot review). |
| repo-config/ruleset-develop.json | Codify develop branch ruleset (squash-only + linear history, required checks, signatures). |
| repo-config/README.md | Document how to apply/audit repo configuration and required-check lockstep. |
| repo-config/configure.sh | Add idempotent apply/check script to enforce/audit rulesets, settings, and secret names. |
| README.md | Update release notes to 1.5 and remove outdated CI/badge/contributing details. |
| LanguageTags.code-workspace | Remove duplicate workspace spell dictionary in favor of cspell.json. |
| HISTORY.md | Add 1.5 release notes focused on CI/CD and repo hardening changes. |
| cspell.json | Introduce repo-wide CSpell config and word list shared by editor/CLI/CI. |
| CODESTYLE.md | Update formatting/lint/spell guidance to reflect enforced CI tooling and repo state. |
| AGENTS.md | Point CI/CD rules to WORKFLOW.md and update contributor-facing workflow/tooling guidance. |
| .vscode/tasks.json | Add codegen tasks and adjust task documentation comments. |
| .github/workflows/validate-task.yml | Add reusable validation gate (unit tests + formatting/lint/spell/actionlint). |
| .github/workflows/test-pull-request.yml | Switch PR gating to push-based CI with reusable validate + smoke build + required aggregator. |
| .github/workflows/run-periodic-codegen-pull-request.yml | Update daily codegen workflow docs/concurrency rationale. |
| .github/workflows/run-codegen-pull-request-task.yml | Clarify dual-target codegen behavior and tighten step documentation. |
| .github/workflows/publish-release.yml | Move to branch-scoped self-publishing on shipped-input changes + manual dispatch. |
| .github/workflows/merge-bot-pull-request.yml | Update bot merge behavior to auto-merge Dependabot/codegen broadly under required checks. |
| .github/workflows/get-version-task.yml | Remove (versioning now inlined into build/release task). |
| .github/workflows/build-release-task.yml | Inline versioning + build + OIDC NuGet publish + GitHub release + artifact cleanup. |
| .github/workflows/build-nugetlibrary-task.yml | Remove (superseded by unified build/release task). |
| .github/workflows/build-datebadge-task.yml | Remove (date badge workflow removed from release model). |
| .github/dependabot.yml | Update comments to match dual-target bot/update model and new workflow set. |
| .github/copilot-instructions.md | Update references to CODESTYLE sections and trim template-specific guidance. |
| .editorconfig | Minor comment updates in .NET-only section. |
Two small doc corrections from Copilot's review of the promotion PR: reorder D9.5/D9.6 in WORKFLOW.md, and fix a lowercase sentence start in repo-config/README.md. The snupkg note was a false positive (the 1.5.1 publish log confirms the .snupkg was pushed to the symbol endpoint). 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This was referenced Jun 29, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Promotes
developtomainfor the 1.5 stable release.What this ships
validate-taskgating both the PR and the publisher, keyless OIDC NuGet publishing, andrepo-config/config-as-code. See WORKFLOW.md.build-release-task.yml.Verified on develop
The 1.5 prerelease published end-to-end from develop:
ptr727.LanguageTags 1.5.1-gb945a2bdf1(NuGet prerelease +.snupkg) and a matching GitHub prerelease release. OIDC trusted publishing works against the corrected policy.On merge
version.jsonis a shipped input, so merging this tomain(merge commit) auto-publishes the 1.5 stable release to NuGet.org. No library API changes.🤖 Generated with Claude Code