Skip to content

Promote develop to main#423

Merged
ptr727 merged 2 commits into
mainfrom
develop
Jul 18, 2026
Merged

Promote develop to main#423
ptr727 merged 2 commits into
mainfrom
develop

Conversation

@ptr727

@ptr727 ptr727 commented Jul 18, 2026

Copy link
Copy Markdown
Owner

Promotion of the WORKFLOW.md drift fix to main.

Contents

PR Change
#422 Correct the 5D audit references (configure.sh check/apply -> AUDIT.md) and the NUGET_USERNAME secret store

Closes #421

What was fixed

  1. configure.sh check / apply do not exist. The script's interface is [owner/repo] [release|operational], so check parsed as a repository name -- acting on the wrong target rather than erroring. Auditing moved to AUDIT.md as a read-only procedure; configure.sh only applies.
  2. NUGET_USERNAME store. WORKFLOW.md claimed Actions-only while spec/secrets.json and AUDIT.md claimed both. Resolved in favor of both, matching the fleet hub's canonical nuget-oidc mechanism and live repository state (the name is present in both stores).

Two further accuracy fixes came out of review: the NuGet.org trusted-publishing policy is now correctly described as sitting outside AUDIT.md's drift report, and the configure.sh model argument note now covers the no-registry fallback to release.

Release impact: no auto-publish

Docs-only. No shipped input (Utilities/**, version.json, Directory.Build.props, Directory.Packages.props) is touched, so this will correctly not trigger a stable release. NuGet stays at 4.0.18, whose library content is already identical to main.

Fixes both items in #421, surfaced by Copilot review on #420.

## 1. `configure.sh check` / `apply` do not exist

`WORKFLOW.md` referenced subcommands the script never implemented. Its
interface is `[owner/repo] [release|operational]`, so `configure.sh
check` parses `check` as a **repository name** -- it acts on the wrong
target rather than erroring, which is why this was worth fixing rather
than leaving.

Auditing also moved to [`AUDIT.md`](../blob/develop/AUDIT.md) as a
read-only procedure; `configure.sh` now only applies. Updated:

- **5D Configuration audit** -- points at the AUDIT.md procedure
- **Validation** (section 6) -- AUDIT.md audits read-only, `configure.sh
[owner/repo] [release|operational]` applies
- Two residual phrases that still described the script as the auditor
("applied and audited by an idempotent `gh api` script", "the script
flags it as a manual verification item")

## 2. `NUGET_USERNAME` secret store

`WORKFLOW.md` said Actions-store-only; `spec/secrets.json` and
`AUDIT.md` say both stores. Resolved in favor of both, on two pieces of
evidence:

- The fleet hub's canonical `nuget-oidc` mechanism in
`ProjectTemplate/spec/secrets.json` declares `"stores": ["actions",
"dependabot"]`, and this repo's spec is a carry of it
- Live repository state has the name in both stores

```
actions:    CODECOV_TOKEN CODEGEN_APP_CLIENT_ID CODEGEN_APP_PRIVATE_KEY NUGET_USERNAME
dependabot: CODECOV_TOKEN CODEGEN_APP_CLIENT_ID CODEGEN_APP_PRIVATE_KEY NUGET_USERNAME
```

So `WORKFLOW.md` was the outlier. It now states both stores and cites
the spec it follows.

Worth recording: Copilot predicted this would make the self-audit report
a false defect. It would not -- the secret is present in both stores, so
the audit passes today. The defect was purely that three documents
disagreed.

## Correction to the issue's fleet note

#421 speculated these might need upstream fixes too. Checked, and they
do not: ProjectTemplate's `WORKFLOW.md` has no `configure.sh` subcommand
references and no NuGet publish at all. Both drifts are local to this
repo.

## Verification

- No `configure.sh check|apply` references remain
- All three link targets resolve (`AUDIT.md`, `spec/secrets.json`,
`repo-config/configure.sh`)
- CRLF preserved; docs-only, no shipped input, so no release impact

---------

Co-authored-by: Claude Opus 4.8 (1M context) <[email protected]>
Copilot AI review requested due to automatic review settings July 18, 2026 17:42
@codecov

codecov Bot commented Jul 18, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 66.89%. Comparing base (a46e3cd) to head (f391645).
⚠️ Report is 53 commits behind head on main.

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #423   +/-   ##
=======================================
  Coverage   66.89%   66.89%           
=======================================
  Files          13       13           
  Lines        1160     1160           
  Branches      108      108           
=======================================
  Hits          776      776           
  Misses        338      338           
  Partials       46       46           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Promotes the develop documentation drift fix into main by updating WORKFLOW.md to reflect the current configuration audit flow, configure.sh interface, and NUGET_USERNAME secret-store requirements.

Changes:

  • Replace stale repo-config/configure.sh check|apply references with the read-only audit procedure in AUDIT.md.
  • Document NUGET_USERNAME as required in both Actions and Dependabot secret stores, consistent with spec/secrets.json and AUDIT.md.
  • Clarify that the NuGet.org trusted-publishing policy is a manual checklist item outside the drift report, and document configure.sh [owner/repo] [release|operational] defaults.

Comment thread WORKFLOW.md Outdated
Comment thread WORKFLOW.md Outdated
Follow-up to #422, from Copilot review on the promotion PR #423.

`AUDIT.md` is explicitly read-only: its secrets check is

```sh
grep -qx "$s" <<<"$names" && echo "$store/$s: present" || echo "$store/$s: MISSING (defect)"
```

-- `echo`-based, with no defined non-zero exit contract. But two
`WORKFLOW.md` sentences still said the audit "asserts" the names exist
and "fail[s] if it cannot query them". That wording is a leftover from
when `configure.sh check` performed the audit and exited non-zero on
drift; #422 moved the audit to AUDIT.md but left these two clauses
describing the old behavior.

Both now describe what AUDIT.md actually does: check the names, and
report a missing name or a failed query as a defect. The
App-installation sentence was adjusted for the same reason ("notes
rather than fails" -> "notes rather than reports a defect").

Docs-only; no shipped input, so no release impact.

Co-authored-by: Claude Opus 4.8 (1M context) <[email protected]>
Copilot AI review requested due to automatic review settings July 18, 2026 17:47

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 1 out of 1 changed files in this pull request and generated 1 comment.

Comment thread WORKFLOW.md
@ptr727
ptr727 merged commit ef9b8a3 into main Jul 18, 2026
12 checks passed
ptr727 added a commit that referenced this pull request Jul 18, 2026
Closes the terminology nit Copilot raised on #423, which I deferred
there as out of scope for that promotion.

`strict-off` appeared exactly once in `WORKFLOW.md` (the 5D audit
summary). Section 6 spells the same setting out twice:

- `main`: `"require branches up to date before merging" is **off**`
- `develop`: `"up to date" is **off**`

The summary now uses the section 6 phrasing, so both places name the
setting identically.

The word "strict" survives at line 646 (`so the strict check would fail
every release`), which is correct -- that sentence is explaining *why*
the setting is off, and "the strict check" is GitHub's own term for the
behavior.

Docs-only; no shipped input, so no release impact.

---------

Co-authored-by: Claude Opus 4.8 (1M context) <[email protected]>
@ptr727 ptr727 mentioned this pull request Jul 18, 2026
ptr727 added a commit that referenced this pull request Jul 18, 2026
Promotion of #425 to `main`.

## Contents

| PR | Change |
| --- | --- |
| #425 | Spell out the up-to-date ruleset setting in the 5D audit
summary |

Replaces the one-off `strict-off` term with section 6's phrasing
(`"require branches up to date before merging"` **off**), so the audit
summary and the ruleset description name the setting identically. Review
also caught that the first attempt split the quoted label across a line
break, making it unsearchable -- fixed, and the paragraph reflowed to
the file's ~105-character width after earlier edits had left a
142-character line.

This closes out the terminology finding Copilot raised on #423, which
was deferred there as out of scope for that promotion.

## Release impact: no auto-publish

Docs-only. No shipped input touched, so no stable release fires. NuGet
stays at 4.0.18.
ptr727-codegen Bot pushed a commit to ptr727/LanguageTags that referenced this pull request Jul 21, 2026
Updated [ptr727.Utilities](https://github.com/ptr727/Utilities) from
4.0.18 to 4.0.28.

<details>
<summary>Release notes</summary>

_Sourced from [ptr727.Utilities's
releases](https://github.com/ptr727/Utilities/releases)._

## 4.0.28

## What's Changed
* Bump the nuget-deps group with 3 updates by @​dependabot[bot] in
ptr727/Utilities#411
* Document the README + HISTORY cspell CI scope in CODESTYLE by @​ptr727
in ptr727/Utilities#413
* Document the README + HISTORY cspell CI scope (main-only) by @​ptr727
in ptr727/Utilities#414
* Bump actions/setup-dotnet from 5.4.0 to 6.0.0 in the actions-deps
group by @​dependabot[bot] in
ptr727/Utilities#415
* Bump actions/setup-dotnet from 5.4.0 to 6.0.0 in the actions-deps
group by @​dependabot[bot] in
ptr727/Utilities#416
* Refresh repo-config carry to current reference; add self-audit carry
by @​ptr727 in ptr727/Utilities#417
* Remove repo-wide analyzer relaxation and honor test cancellation by
@​ptr727 in ptr727/Utilities#418
* Add Codecov coverage shield to the README build status by @​ptr727 in
ptr727/Utilities#419
* Promote develop to main by @​ptr727 in
ptr727/Utilities#420
* Correct WORKFLOW.md audit flow and NUGET_USERNAME secret store by
@​ptr727 in ptr727/Utilities#422
* Describe the 5D audit as reporting defects, not failing by @​ptr727 in
ptr727/Utilities#424
* Promote develop to main by @​ptr727 in
ptr727/Utilities#423
* Spell out the up-to-date ruleset setting in the 5D audit summary by
@​ptr727 in ptr727/Utilities#425
* Promote develop to main by @​ptr727 in
ptr727/Utilities#426
* Bump DavidAnson/markdownlint-cli2-action from 24.0.0 to 24.1.0 in the
actions-deps group by @​dependabot[bot] in
ptr727/Utilities#429
* Bump the nuget-deps group with 1 update by @​dependabot[bot] in
ptr727/Utilities#431


**Full Changelog**:
ptr727/Utilities@4.0.18...4.0.28

Commits viewable in [compare
view](ptr727/Utilities@4.0.18...4.0.28).
</details>

[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=ptr727.Utilities&package-manager=nuget&previous-version=4.0.18&new-version=4.0.28)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

WORKFLOW.md drift: stale configure.sh subcommands and NUGET_USERNAME secret store

2 participants