Skip to content

Describe the 5D audit as reporting defects, not failing#424

Merged
ptr727 merged 1 commit into
developfrom
docs/audit-reporting-wording
Jul 18, 2026
Merged

Describe the 5D audit as reporting defects, not failing#424
ptr727 merged 1 commit into
developfrom
docs/audit-reporting-wording

Conversation

@ptr727

@ptr727 ptr727 commented Jul 18, 2026

Copy link
Copy Markdown
Owner

Follow-up to #422, from Copilot review on the promotion PR #423.

AUDIT.md is explicitly read-only: its secrets check is

grep -qx "$s" <<<"$names" && echo "$store/$s: present" || echo "$store/$s: MISSING (defect)"

-- echo-based, with no defined non-zero exit contract. But two WORKFLOW.md sentences still said the audit "asserts" the names exist and "fail[s] if it cannot query them". That wording is a leftover from when configure.sh check performed the audit and exited non-zero on drift; #422 moved the audit to AUDIT.md but left these two clauses describing the old behavior.

Both now describe what AUDIT.md actually does: check the names, and report a missing name or a failed query as a defect. The App-installation sentence was adjusted for the same reason ("notes rather than fails" -> "notes rather than reports a defect").

Docs-only; no shipped input, so no release impact.

AUDIT.md is a read-only procedure: its secrets check echoes
"MISSING (defect)" and defines no non-zero exit contract. Two sentences
in WORKFLOW.md still said the audit "asserts" names exist and "fails" if
it cannot query them, wording inherited from when configure.sh performed
the audit and exited non-zero on drift.

Describe the behavior AUDIT.md actually has: it checks the names and
reports a missing name or a failed query as a defect.

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
Copilot AI review requested due to automatic review settings July 18, 2026 17:45

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates WORKFLOW.md to accurately describe the 5D configuration audit as a read-only procedure that reports defects (missing secret names or failed queries) rather than asserting and failing, aligning the documentation with AUDIT.md’s echo-based behavior.

Changes:

  • Reword the 5D audit description to “checks … reporting … as a defect” instead of “asserts … failing”.
  • Clarify the GitHub App installation check wording to reflect “notes” vs “reports a defect” behavior.

@codecov

codecov Bot commented Jul 18, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 66.89%. Comparing base (d75a240) to head (ad45bb4).

Additional details and impacted files
@@           Coverage Diff            @@
##           develop     #424   +/-   ##
========================================
  Coverage    66.89%   66.89%           
========================================
  Files           13       13           
  Lines         1160     1160           
  Branches       108      108           
========================================
  Hits           776      776           
  Misses         338      338           
  Partials        46       46           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@ptr727
ptr727 merged commit f391645 into develop Jul 18, 2026
12 checks passed
@ptr727
ptr727 deleted the docs/audit-reporting-wording branch July 18, 2026 17:47
ptr727-codegen Bot pushed a commit to ptr727/LanguageTags that referenced this pull request Jul 21, 2026
Updated [ptr727.Utilities](https://github.com/ptr727/Utilities) from
4.0.18 to 4.0.28.

<details>
<summary>Release notes</summary>

_Sourced from [ptr727.Utilities's
releases](https://github.com/ptr727/Utilities/releases)._

## 4.0.28

## What's Changed
* Bump the nuget-deps group with 3 updates by @​dependabot[bot] in
ptr727/Utilities#411
* Document the README + HISTORY cspell CI scope in CODESTYLE by @​ptr727
in ptr727/Utilities#413
* Document the README + HISTORY cspell CI scope (main-only) by @​ptr727
in ptr727/Utilities#414
* Bump actions/setup-dotnet from 5.4.0 to 6.0.0 in the actions-deps
group by @​dependabot[bot] in
ptr727/Utilities#415
* Bump actions/setup-dotnet from 5.4.0 to 6.0.0 in the actions-deps
group by @​dependabot[bot] in
ptr727/Utilities#416
* Refresh repo-config carry to current reference; add self-audit carry
by @​ptr727 in ptr727/Utilities#417
* Remove repo-wide analyzer relaxation and honor test cancellation by
@​ptr727 in ptr727/Utilities#418
* Add Codecov coverage shield to the README build status by @​ptr727 in
ptr727/Utilities#419
* Promote develop to main by @​ptr727 in
ptr727/Utilities#420
* Correct WORKFLOW.md audit flow and NUGET_USERNAME secret store by
@​ptr727 in ptr727/Utilities#422
* Describe the 5D audit as reporting defects, not failing by @​ptr727 in
ptr727/Utilities#424
* Promote develop to main by @​ptr727 in
ptr727/Utilities#423
* Spell out the up-to-date ruleset setting in the 5D audit summary by
@​ptr727 in ptr727/Utilities#425
* Promote develop to main by @​ptr727 in
ptr727/Utilities#426
* Bump DavidAnson/markdownlint-cli2-action from 24.0.0 to 24.1.0 in the
actions-deps group by @​dependabot[bot] in
ptr727/Utilities#429
* Bump the nuget-deps group with 1 update by @​dependabot[bot] in
ptr727/Utilities#431


**Full Changelog**:
ptr727/Utilities@4.0.18...4.0.28

Commits viewable in [compare
view](ptr727/Utilities@4.0.18...4.0.28).
</details>

[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=ptr727.Utilities&package-manager=nuget&previous-version=4.0.18&new-version=4.0.28)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants