Correct WORKFLOW.md audit flow and NUGET_USERNAME secret store#422
Merged
Conversation
Two documentation drifts surfaced by Copilot review on #420, both verified against the tree and live repository state. The 5D audit and validation sections referenced `configure.sh check` and `configure.sh apply`, subcommands the script does not implement. Its interface is `[owner/repo] [release|operational]`, so `check` would be parsed as a repository name and silently act on the wrong target rather than erroring. Auditing also moved to AUDIT.md as a read-only procedure; configure.sh now only applies. Point the audit references at AUDIT.md and describe configure.sh with its actual argument form. NUGET_USERNAME was documented as Actions-store-only while spec/secrets.json and AUDIT.md both claim the Actions and Dependabot stores. The fleet hub's canonical nuget-oidc mechanism declares both, and the live repository carries the name in both stores, so WORKFLOW.md was the outlier; align it and cite the spec it follows. Both drifts are local to this repo. ProjectTemplate's WORKFLOW.md has no configure.sh subcommand references and no NuGet publish, so neither needs an upstream fix. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## develop #422 +/- ##
========================================
Coverage 66.89% 66.89%
========================================
Files 13 13
Lines 1160 1160
Branches 108 108
========================================
Hits 776 776
Misses 338 338
Partials 46 46 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Contributor
There was a problem hiding this comment.
Pull request overview
This PR corrects documentation drift in WORKFLOW.md so the repository-configuration audit/apply flow matches the actual repo tooling (AUDIT.md for read-only auditing and repo-config/configure.sh for applying baseline config), and aligns the documented NUGET_USERNAME secret-store requirements with the repo’s secret specification.
Changes:
- Update the 5D “Configuration audit” instructions to point to the read-only
AUDIT.mdprocedure instead of non-existentconfigure.sh check|applysubcommands. - Document
NUGET_USERNAMEas required in both Actions and Dependabot secret stores, consistent withspec/secrets.json/AUDIT.md. - Rewrite the “Validation” paragraph to reflect “audit via
AUDIT.md+ apply viarepo-config/configure.sh [owner/repo] [release|operational]”.
…back Two accuracy fixes from Copilot review. The 5D section said the audit "records" the NuGet.org trusted-publishing policy as a manual item, but AUDIT.md does not mention that policy at all - it checks settings, rulesets, and secret names only. The previous wording attributed it to configure.sh, and rewording it to "the audit" moved the inaccurate claim onto AUDIT.md rather than removing it. State plainly that the policy sits outside the drift report as a manual checklist item. The configure.sh model argument note omitted the standalone case: with no registry file the script warns and defaults to release, rather than performing a registry lookup. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
This was referenced Jul 18, 2026
Merged
ptr727
added a commit
that referenced
this pull request
Jul 18, 2026
Follow-up to #422, from Copilot review on the promotion PR #423. `AUDIT.md` is explicitly read-only: its secrets check is ```sh grep -qx "$s" <<<"$names" && echo "$store/$s: present" || echo "$store/$s: MISSING (defect)" ``` -- `echo`-based, with no defined non-zero exit contract. But two `WORKFLOW.md` sentences still said the audit "asserts" the names exist and "fail[s] if it cannot query them". That wording is a leftover from when `configure.sh check` performed the audit and exited non-zero on drift; #422 moved the audit to AUDIT.md but left these two clauses describing the old behavior. Both now describe what AUDIT.md actually does: check the names, and report a missing name or a failed query as a defect. The App-installation sentence was adjusted for the same reason ("notes rather than fails" -> "notes rather than reports a defect"). Docs-only; no shipped input, so no release impact. Co-authored-by: Claude Opus 4.8 (1M context) <[email protected]>
ptr727
added a commit
that referenced
this pull request
Jul 18, 2026
Promotion of the `WORKFLOW.md` drift fix to `main`. ## Contents | PR | Change | | --- | --- | | #422 | Correct the 5D audit references (`configure.sh check`/`apply` -> AUDIT.md) and the `NUGET_USERNAME` secret store | Closes #421 ## What was fixed 1. **`configure.sh check` / `apply` do not exist.** The script's interface is `[owner/repo] [release|operational]`, so `check` parsed as a *repository name* -- acting on the wrong target rather than erroring. Auditing moved to `AUDIT.md` as a read-only procedure; `configure.sh` only applies. 2. **`NUGET_USERNAME` store.** `WORKFLOW.md` claimed Actions-only while `spec/secrets.json` and `AUDIT.md` claimed both. Resolved in favor of both, matching the fleet hub's canonical `nuget-oidc` mechanism and live repository state (the name is present in both stores). Two further accuracy fixes came out of review: the NuGet.org trusted-publishing policy is now correctly described as sitting *outside* AUDIT.md's drift report, and the `configure.sh` model argument note now covers the no-registry fallback to `release`. ## Release impact: no auto-publish Docs-only. No shipped input (`Utilities/**`, `version.json`, `Directory.Build.props`, `Directory.Packages.props`) is touched, so this will correctly not trigger a stable release. NuGet stays at 4.0.18, whose library content is already identical to `main`.
This was referenced Jul 21, 2026
ptr727-codegen Bot
pushed a commit
to ptr727/LanguageTags
that referenced
this pull request
Jul 21, 2026
Updated [ptr727.Utilities](https://github.com/ptr727/Utilities) from 4.0.18 to 4.0.28. <details> <summary>Release notes</summary> _Sourced from [ptr727.Utilities's releases](https://github.com/ptr727/Utilities/releases)._ ## 4.0.28 ## What's Changed * Bump the nuget-deps group with 3 updates by @dependabot[bot] in ptr727/Utilities#411 * Document the README + HISTORY cspell CI scope in CODESTYLE by @ptr727 in ptr727/Utilities#413 * Document the README + HISTORY cspell CI scope (main-only) by @ptr727 in ptr727/Utilities#414 * Bump actions/setup-dotnet from 5.4.0 to 6.0.0 in the actions-deps group by @dependabot[bot] in ptr727/Utilities#415 * Bump actions/setup-dotnet from 5.4.0 to 6.0.0 in the actions-deps group by @dependabot[bot] in ptr727/Utilities#416 * Refresh repo-config carry to current reference; add self-audit carry by @ptr727 in ptr727/Utilities#417 * Remove repo-wide analyzer relaxation and honor test cancellation by @ptr727 in ptr727/Utilities#418 * Add Codecov coverage shield to the README build status by @ptr727 in ptr727/Utilities#419 * Promote develop to main by @ptr727 in ptr727/Utilities#420 * Correct WORKFLOW.md audit flow and NUGET_USERNAME secret store by @ptr727 in ptr727/Utilities#422 * Describe the 5D audit as reporting defects, not failing by @ptr727 in ptr727/Utilities#424 * Promote develop to main by @ptr727 in ptr727/Utilities#423 * Spell out the up-to-date ruleset setting in the 5D audit summary by @ptr727 in ptr727/Utilities#425 * Promote develop to main by @ptr727 in ptr727/Utilities#426 * Bump DavidAnson/markdownlint-cli2-action from 24.0.0 to 24.1.0 in the actions-deps group by @dependabot[bot] in ptr727/Utilities#429 * Bump the nuget-deps group with 1 update by @dependabot[bot] in ptr727/Utilities#431 **Full Changelog**: ptr727/Utilities@4.0.18...4.0.28 Commits viewable in [compare view](ptr727/Utilities@4.0.18...4.0.28). </details> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions </details> Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
This was referenced Jul 21, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes both items in #421, surfaced by Copilot review on #420.
1.
configure.sh check/applydo not existWORKFLOW.mdreferenced subcommands the script never implemented. Its interface is[owner/repo] [release|operational], soconfigure.sh checkparsescheckas a repository name -- it acts on the wrong target rather than erroring, which is why this was worth fixing rather than leaving.Auditing also moved to
AUDIT.mdas a read-only procedure;configure.shnow only applies. Updated:configure.sh [owner/repo] [release|operational]appliesgh apiscript", "the script flags it as a manual verification item")2.
NUGET_USERNAMEsecret storeWORKFLOW.mdsaid Actions-store-only;spec/secrets.jsonandAUDIT.mdsay both stores. Resolved in favor of both, on two pieces of evidence:nuget-oidcmechanism inProjectTemplate/spec/secrets.jsondeclares"stores": ["actions", "dependabot"], and this repo's spec is a carry of itSo
WORKFLOW.mdwas the outlier. It now states both stores and cites the spec it follows.Worth recording: Copilot predicted this would make the self-audit report a false defect. It would not -- the secret is present in both stores, so the audit passes today. The defect was purely that three documents disagreed.
Correction to the issue's fleet note
#421 speculated these might need upstream fixes too. Checked, and they do not: ProjectTemplate's
WORKFLOW.mdhas noconfigure.shsubcommand references and no NuGet publish at all. Both drifts are local to this repo.Verification
configure.sh check|applyreferences remainAUDIT.md,spec/secrets.json,repo-config/configure.sh)