Conversation
Fixes both items in #421, surfaced by Copilot review on #420. ## 1. `configure.sh check` / `apply` do not exist `WORKFLOW.md` referenced subcommands the script never implemented. Its interface is `[owner/repo] [release|operational]`, so `configure.sh check` parses `check` as a **repository name** -- it acts on the wrong target rather than erroring, which is why this was worth fixing rather than leaving. Auditing also moved to [`AUDIT.md`](../blob/develop/AUDIT.md) as a read-only procedure; `configure.sh` now only applies. Updated: - **5D Configuration audit** -- points at the AUDIT.md procedure - **Validation** (section 6) -- AUDIT.md audits read-only, `configure.sh [owner/repo] [release|operational]` applies - Two residual phrases that still described the script as the auditor ("applied and audited by an idempotent `gh api` script", "the script flags it as a manual verification item") ## 2. `NUGET_USERNAME` secret store `WORKFLOW.md` said Actions-store-only; `spec/secrets.json` and `AUDIT.md` say both stores. Resolved in favor of both, on two pieces of evidence: - The fleet hub's canonical `nuget-oidc` mechanism in `ProjectTemplate/spec/secrets.json` declares `"stores": ["actions", "dependabot"]`, and this repo's spec is a carry of it - Live repository state has the name in both stores ``` actions: CODECOV_TOKEN CODEGEN_APP_CLIENT_ID CODEGEN_APP_PRIVATE_KEY NUGET_USERNAME dependabot: CODECOV_TOKEN CODEGEN_APP_CLIENT_ID CODEGEN_APP_PRIVATE_KEY NUGET_USERNAME ``` So `WORKFLOW.md` was the outlier. It now states both stores and cites the spec it follows. Worth recording: Copilot predicted this would make the self-audit report a false defect. It would not -- the secret is present in both stores, so the audit passes today. The defect was purely that three documents disagreed. ## Correction to the issue's fleet note #421 speculated these might need upstream fixes too. Checked, and they do not: ProjectTemplate's `WORKFLOW.md` has no `configure.sh` subcommand references and no NuGet publish at all. Both drifts are local to this repo. ## Verification - No `configure.sh check|apply` references remain - All three link targets resolve (`AUDIT.md`, `spec/secrets.json`, `repo-config/configure.sh`) - CRLF preserved; docs-only, no shipped input, so no release impact --------- Co-authored-by: Claude Opus 4.8 (1M context) <[email protected]>
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #423 +/- ##
=======================================
Coverage 66.89% 66.89%
=======================================
Files 13 13
Lines 1160 1160
Branches 108 108
=======================================
Hits 776 776
Misses 338 338
Partials 46 46 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Contributor
There was a problem hiding this comment.
Pull request overview
Promotes the develop documentation drift fix into main by updating WORKFLOW.md to reflect the current configuration audit flow, configure.sh interface, and NUGET_USERNAME secret-store requirements.
Changes:
- Replace stale
repo-config/configure.sh check|applyreferences with the read-only audit procedure inAUDIT.md. - Document
NUGET_USERNAMEas required in both Actions and Dependabot secret stores, consistent withspec/secrets.jsonandAUDIT.md. - Clarify that the NuGet.org trusted-publishing policy is a manual checklist item outside the drift report, and document
configure.sh [owner/repo] [release|operational]defaults.
Follow-up to #422, from Copilot review on the promotion PR #423. `AUDIT.md` is explicitly read-only: its secrets check is ```sh grep -qx "$s" <<<"$names" && echo "$store/$s: present" || echo "$store/$s: MISSING (defect)" ``` -- `echo`-based, with no defined non-zero exit contract. But two `WORKFLOW.md` sentences still said the audit "asserts" the names exist and "fail[s] if it cannot query them". That wording is a leftover from when `configure.sh check` performed the audit and exited non-zero on drift; #422 moved the audit to AUDIT.md but left these two clauses describing the old behavior. Both now describe what AUDIT.md actually does: check the names, and report a missing name or a failed query as a defect. The App-installation sentence was adjusted for the same reason ("notes rather than fails" -> "notes rather than reports a defect"). Docs-only; no shipped input, so no release impact. Co-authored-by: Claude Opus 4.8 (1M context) <[email protected]>
ptr727
added a commit
that referenced
this pull request
Jul 18, 2026
Closes the terminology nit Copilot raised on #423, which I deferred there as out of scope for that promotion. `strict-off` appeared exactly once in `WORKFLOW.md` (the 5D audit summary). Section 6 spells the same setting out twice: - `main`: `"require branches up to date before merging" is **off**` - `develop`: `"up to date" is **off**` The summary now uses the section 6 phrasing, so both places name the setting identically. The word "strict" survives at line 646 (`so the strict check would fail every release`), which is correct -- that sentence is explaining *why* the setting is off, and "the strict check" is GitHub's own term for the behavior. Docs-only; no shipped input, so no release impact. --------- Co-authored-by: Claude Opus 4.8 (1M context) <[email protected]>
Merged
ptr727
added a commit
that referenced
this pull request
Jul 18, 2026
Promotion of #425 to `main`. ## Contents | PR | Change | | --- | --- | | #425 | Spell out the up-to-date ruleset setting in the 5D audit summary | Replaces the one-off `strict-off` term with section 6's phrasing (`"require branches up to date before merging"` **off**), so the audit summary and the ruleset description name the setting identically. Review also caught that the first attempt split the quoted label across a line break, making it unsearchable -- fixed, and the paragraph reflowed to the file's ~105-character width after earlier edits had left a 142-character line. This closes out the terminology finding Copilot raised on #423, which was deferred there as out of scope for that promotion. ## Release impact: no auto-publish Docs-only. No shipped input touched, so no stable release fires. NuGet stays at 4.0.18.
This was referenced Jul 21, 2026
ptr727-codegen Bot
pushed a commit
to ptr727/LanguageTags
that referenced
this pull request
Jul 21, 2026
Updated [ptr727.Utilities](https://github.com/ptr727/Utilities) from 4.0.18 to 4.0.28. <details> <summary>Release notes</summary> _Sourced from [ptr727.Utilities's releases](https://github.com/ptr727/Utilities/releases)._ ## 4.0.28 ## What's Changed * Bump the nuget-deps group with 3 updates by @dependabot[bot] in ptr727/Utilities#411 * Document the README + HISTORY cspell CI scope in CODESTYLE by @ptr727 in ptr727/Utilities#413 * Document the README + HISTORY cspell CI scope (main-only) by @ptr727 in ptr727/Utilities#414 * Bump actions/setup-dotnet from 5.4.0 to 6.0.0 in the actions-deps group by @dependabot[bot] in ptr727/Utilities#415 * Bump actions/setup-dotnet from 5.4.0 to 6.0.0 in the actions-deps group by @dependabot[bot] in ptr727/Utilities#416 * Refresh repo-config carry to current reference; add self-audit carry by @ptr727 in ptr727/Utilities#417 * Remove repo-wide analyzer relaxation and honor test cancellation by @ptr727 in ptr727/Utilities#418 * Add Codecov coverage shield to the README build status by @ptr727 in ptr727/Utilities#419 * Promote develop to main by @ptr727 in ptr727/Utilities#420 * Correct WORKFLOW.md audit flow and NUGET_USERNAME secret store by @ptr727 in ptr727/Utilities#422 * Describe the 5D audit as reporting defects, not failing by @ptr727 in ptr727/Utilities#424 * Promote develop to main by @ptr727 in ptr727/Utilities#423 * Spell out the up-to-date ruleset setting in the 5D audit summary by @ptr727 in ptr727/Utilities#425 * Promote develop to main by @ptr727 in ptr727/Utilities#426 * Bump DavidAnson/markdownlint-cli2-action from 24.0.0 to 24.1.0 in the actions-deps group by @dependabot[bot] in ptr727/Utilities#429 * Bump the nuget-deps group with 1 update by @dependabot[bot] in ptr727/Utilities#431 **Full Changelog**: ptr727/Utilities@4.0.18...4.0.28 Commits viewable in [compare view](ptr727/Utilities@4.0.18...4.0.28). </details> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions </details> Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
This was referenced Jul 21, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Promotion of the
WORKFLOW.mddrift fix tomain.Contents
configure.sh check/apply-> AUDIT.md) and theNUGET_USERNAMEsecret storeCloses #421
What was fixed
configure.sh check/applydo not exist. The script's interface is[owner/repo] [release|operational], socheckparsed as a repository name -- acting on the wrong target rather than erroring. Auditing moved toAUDIT.mdas a read-only procedure;configure.shonly applies.NUGET_USERNAMEstore.WORKFLOW.mdclaimed Actions-only whilespec/secrets.jsonandAUDIT.mdclaimed both. Resolved in favor of both, matching the fleet hub's canonicalnuget-oidcmechanism and live repository state (the name is present in both stores).Two further accuracy fixes came out of review: the NuGet.org trusted-publishing policy is now correctly described as sitting outside AUDIT.md's drift report, and the
configure.shmodel argument note now covers the no-registry fallback torelease.Release impact: no auto-publish
Docs-only. No shipped input (
Utilities/**,version.json,Directory.Build.props,Directory.Packages.props) is touched, so this will correctly not trigger a stable release. NuGet stays at 4.0.18, whose library content is already identical tomain.