Skip to content

Correct WORKFLOW.md audit flow and NUGET_USERNAME secret store#422

Merged
ptr727 merged 2 commits into
developfrom
docs/workflow-md-drift
Jul 18, 2026
Merged

Correct WORKFLOW.md audit flow and NUGET_USERNAME secret store#422
ptr727 merged 2 commits into
developfrom
docs/workflow-md-drift

Conversation

@ptr727

@ptr727 ptr727 commented Jul 18, 2026

Copy link
Copy Markdown
Owner

Fixes both items in #421, surfaced by Copilot review on #420.

1. configure.sh check / apply do not exist

WORKFLOW.md referenced subcommands the script never implemented. Its interface is [owner/repo] [release|operational], so configure.sh check parses check as a repository name -- it acts on the wrong target rather than erroring, which is why this was worth fixing rather than leaving.

Auditing also moved to AUDIT.md as a read-only procedure; configure.sh now only applies. Updated:

  • 5D Configuration audit -- points at the AUDIT.md procedure
  • Validation (section 6) -- AUDIT.md audits read-only, configure.sh [owner/repo] [release|operational] applies
  • Two residual phrases that still described the script as the auditor ("applied and audited by an idempotent gh api script", "the script flags it as a manual verification item")

2. NUGET_USERNAME secret store

WORKFLOW.md said Actions-store-only; spec/secrets.json and AUDIT.md say both stores. Resolved in favor of both, on two pieces of evidence:

  • The fleet hub's canonical nuget-oidc mechanism in ProjectTemplate/spec/secrets.json declares "stores": ["actions", "dependabot"], and this repo's spec is a carry of it
  • Live repository state has the name in both stores
actions:    CODECOV_TOKEN CODEGEN_APP_CLIENT_ID CODEGEN_APP_PRIVATE_KEY NUGET_USERNAME
dependabot: CODECOV_TOKEN CODEGEN_APP_CLIENT_ID CODEGEN_APP_PRIVATE_KEY NUGET_USERNAME

So WORKFLOW.md was the outlier. It now states both stores and cites the spec it follows.

Worth recording: Copilot predicted this would make the self-audit report a false defect. It would not -- the secret is present in both stores, so the audit passes today. The defect was purely that three documents disagreed.

Correction to the issue's fleet note

#421 speculated these might need upstream fixes too. Checked, and they do not: ProjectTemplate's WORKFLOW.md has no configure.sh subcommand references and no NuGet publish at all. Both drifts are local to this repo.

Verification

  • No configure.sh check|apply references remain
  • All three link targets resolve (AUDIT.md, spec/secrets.json, repo-config/configure.sh)
  • CRLF preserved; docs-only, no shipped input, so no release impact

Two documentation drifts surfaced by Copilot review on #420, both
verified against the tree and live repository state.

The 5D audit and validation sections referenced `configure.sh check` and
`configure.sh apply`, subcommands the script does not implement. Its
interface is `[owner/repo] [release|operational]`, so `check` would be
parsed as a repository name and silently act on the wrong target rather
than erroring. Auditing also moved to AUDIT.md as a read-only procedure;
configure.sh now only applies. Point the audit references at AUDIT.md and
describe configure.sh with its actual argument form.

NUGET_USERNAME was documented as Actions-store-only while
spec/secrets.json and AUDIT.md both claim the Actions and Dependabot
stores. The fleet hub's canonical nuget-oidc mechanism declares both, and
the live repository carries the name in both stores, so WORKFLOW.md was
the outlier; align it and cite the spec it follows.

Both drifts are local to this repo. ProjectTemplate's WORKFLOW.md has no
configure.sh subcommand references and no NuGet publish, so neither needs
an upstream fix.

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
Copilot AI review requested due to automatic review settings July 18, 2026 17:36
@codecov

codecov Bot commented Jul 18, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 66.89%. Comparing base (a46e3cd) to head (2487a13).

Additional details and impacted files
@@           Coverage Diff            @@
##           develop     #422   +/-   ##
========================================
  Coverage    66.89%   66.89%           
========================================
  Files           13       13           
  Lines         1160     1160           
  Branches       108      108           
========================================
  Hits           776      776           
  Misses         338      338           
  Partials        46       46           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR corrects documentation drift in WORKFLOW.md so the repository-configuration audit/apply flow matches the actual repo tooling (AUDIT.md for read-only auditing and repo-config/configure.sh for applying baseline config), and aligns the documented NUGET_USERNAME secret-store requirements with the repo’s secret specification.

Changes:

  • Update the 5D “Configuration audit” instructions to point to the read-only AUDIT.md procedure instead of non-existent configure.sh check|apply subcommands.
  • Document NUGET_USERNAME as required in both Actions and Dependabot secret stores, consistent with spec/secrets.json / AUDIT.md.
  • Rewrite the “Validation” paragraph to reflect “audit via AUDIT.md + apply via repo-config/configure.sh [owner/repo] [release|operational]”.

Comment thread WORKFLOW.md Outdated
Comment thread WORKFLOW.md Outdated
…back

Two accuracy fixes from Copilot review.

The 5D section said the audit "records" the NuGet.org trusted-publishing
policy as a manual item, but AUDIT.md does not mention that policy at all
- it checks settings, rulesets, and secret names only. The previous
wording attributed it to configure.sh, and rewording it to "the audit"
moved the inaccurate claim onto AUDIT.md rather than removing it. State
plainly that the policy sits outside the drift report as a manual
checklist item.

The configure.sh model argument note omitted the standalone case:
with no registry file the script warns and defaults to release, rather
than performing a registry lookup.

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
Copilot AI review requested due to automatic review settings July 18, 2026 17:39

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 1 out of 1 changed files in this pull request and generated no new comments.

@ptr727
ptr727 merged commit d75a240 into develop Jul 18, 2026
12 checks passed
@ptr727
ptr727 deleted the docs/workflow-md-drift branch July 18, 2026 17:42
ptr727 added a commit that referenced this pull request Jul 18, 2026
Follow-up to #422, from Copilot review on the promotion PR #423.

`AUDIT.md` is explicitly read-only: its secrets check is

```sh
grep -qx "$s" <<<"$names" && echo "$store/$s: present" || echo "$store/$s: MISSING (defect)"
```

-- `echo`-based, with no defined non-zero exit contract. But two
`WORKFLOW.md` sentences still said the audit "asserts" the names exist
and "fail[s] if it cannot query them". That wording is a leftover from
when `configure.sh check` performed the audit and exited non-zero on
drift; #422 moved the audit to AUDIT.md but left these two clauses
describing the old behavior.

Both now describe what AUDIT.md actually does: check the names, and
report a missing name or a failed query as a defect. The
App-installation sentence was adjusted for the same reason ("notes
rather than fails" -> "notes rather than reports a defect").

Docs-only; no shipped input, so no release impact.

Co-authored-by: Claude Opus 4.8 (1M context) <[email protected]>
ptr727 added a commit that referenced this pull request Jul 18, 2026
Promotion of the `WORKFLOW.md` drift fix to `main`.

## Contents

| PR | Change |
| --- | --- |
| #422 | Correct the 5D audit references (`configure.sh check`/`apply`
-> AUDIT.md) and the `NUGET_USERNAME` secret store |

Closes #421

## What was fixed

1. **`configure.sh check` / `apply` do not exist.** The script's
interface is `[owner/repo] [release|operational]`, so `check` parsed as
a *repository name* -- acting on the wrong target rather than erroring.
Auditing moved to `AUDIT.md` as a read-only procedure; `configure.sh`
only applies.
2. **`NUGET_USERNAME` store.** `WORKFLOW.md` claimed Actions-only while
`spec/secrets.json` and `AUDIT.md` claimed both. Resolved in favor of
both, matching the fleet hub's canonical `nuget-oidc` mechanism and live
repository state (the name is present in both stores).

Two further accuracy fixes came out of review: the NuGet.org
trusted-publishing policy is now correctly described as sitting
*outside* AUDIT.md's drift report, and the `configure.sh` model argument
note now covers the no-registry fallback to `release`.

## Release impact: no auto-publish

Docs-only. No shipped input (`Utilities/**`, `version.json`,
`Directory.Build.props`, `Directory.Packages.props`) is touched, so this
will correctly not trigger a stable release. NuGet stays at 4.0.18,
whose library content is already identical to `main`.
ptr727-codegen Bot pushed a commit to ptr727/LanguageTags that referenced this pull request Jul 21, 2026
Updated [ptr727.Utilities](https://github.com/ptr727/Utilities) from
4.0.18 to 4.0.28.

<details>
<summary>Release notes</summary>

_Sourced from [ptr727.Utilities's
releases](https://github.com/ptr727/Utilities/releases)._

## 4.0.28

## What's Changed
* Bump the nuget-deps group with 3 updates by @​dependabot[bot] in
ptr727/Utilities#411
* Document the README + HISTORY cspell CI scope in CODESTYLE by @​ptr727
in ptr727/Utilities#413
* Document the README + HISTORY cspell CI scope (main-only) by @​ptr727
in ptr727/Utilities#414
* Bump actions/setup-dotnet from 5.4.0 to 6.0.0 in the actions-deps
group by @​dependabot[bot] in
ptr727/Utilities#415
* Bump actions/setup-dotnet from 5.4.0 to 6.0.0 in the actions-deps
group by @​dependabot[bot] in
ptr727/Utilities#416
* Refresh repo-config carry to current reference; add self-audit carry
by @​ptr727 in ptr727/Utilities#417
* Remove repo-wide analyzer relaxation and honor test cancellation by
@​ptr727 in ptr727/Utilities#418
* Add Codecov coverage shield to the README build status by @​ptr727 in
ptr727/Utilities#419
* Promote develop to main by @​ptr727 in
ptr727/Utilities#420
* Correct WORKFLOW.md audit flow and NUGET_USERNAME secret store by
@​ptr727 in ptr727/Utilities#422
* Describe the 5D audit as reporting defects, not failing by @​ptr727 in
ptr727/Utilities#424
* Promote develop to main by @​ptr727 in
ptr727/Utilities#423
* Spell out the up-to-date ruleset setting in the 5D audit summary by
@​ptr727 in ptr727/Utilities#425
* Promote develop to main by @​ptr727 in
ptr727/Utilities#426
* Bump DavidAnson/markdownlint-cli2-action from 24.0.0 to 24.1.0 in the
actions-deps group by @​dependabot[bot] in
ptr727/Utilities#429
* Bump the nuget-deps group with 1 update by @​dependabot[bot] in
ptr727/Utilities#431


**Full Changelog**:
ptr727/Utilities@4.0.18...4.0.28

Commits viewable in [compare
view](ptr727/Utilities@4.0.18...4.0.28).
</details>

[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=ptr727.Utilities&package-manager=nuget&previous-version=4.0.18&new-version=4.0.28)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants