Describe the 5D audit as reporting defects, not failing#424
Merged
Conversation
AUDIT.md is a read-only procedure: its secrets check echoes "MISSING (defect)" and defines no non-zero exit contract. Two sentences in WORKFLOW.md still said the audit "asserts" names exist and "fails" if it cannot query them, wording inherited from when configure.sh performed the audit and exited non-zero on drift. Describe the behavior AUDIT.md actually has: it checks the names and reports a missing name or a failed query as a defect. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
Contributor
There was a problem hiding this comment.
Pull request overview
Updates WORKFLOW.md to accurately describe the 5D configuration audit as a read-only procedure that reports defects (missing secret names or failed queries) rather than asserting and failing, aligning the documentation with AUDIT.md’s echo-based behavior.
Changes:
- Reword the 5D audit description to “checks … reporting … as a defect” instead of “asserts … failing”.
- Clarify the GitHub App installation check wording to reflect “notes” vs “reports a defect” behavior.
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## develop #424 +/- ##
========================================
Coverage 66.89% 66.89%
========================================
Files 13 13
Lines 1160 1160
Branches 108 108
========================================
Hits 776 776
Misses 338 338
Partials 46 46 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
This was referenced Jul 21, 2026
ptr727-codegen Bot
pushed a commit
to ptr727/LanguageTags
that referenced
this pull request
Jul 21, 2026
Updated [ptr727.Utilities](https://github.com/ptr727/Utilities) from 4.0.18 to 4.0.28. <details> <summary>Release notes</summary> _Sourced from [ptr727.Utilities's releases](https://github.com/ptr727/Utilities/releases)._ ## 4.0.28 ## What's Changed * Bump the nuget-deps group with 3 updates by @dependabot[bot] in ptr727/Utilities#411 * Document the README + HISTORY cspell CI scope in CODESTYLE by @ptr727 in ptr727/Utilities#413 * Document the README + HISTORY cspell CI scope (main-only) by @ptr727 in ptr727/Utilities#414 * Bump actions/setup-dotnet from 5.4.0 to 6.0.0 in the actions-deps group by @dependabot[bot] in ptr727/Utilities#415 * Bump actions/setup-dotnet from 5.4.0 to 6.0.0 in the actions-deps group by @dependabot[bot] in ptr727/Utilities#416 * Refresh repo-config carry to current reference; add self-audit carry by @ptr727 in ptr727/Utilities#417 * Remove repo-wide analyzer relaxation and honor test cancellation by @ptr727 in ptr727/Utilities#418 * Add Codecov coverage shield to the README build status by @ptr727 in ptr727/Utilities#419 * Promote develop to main by @ptr727 in ptr727/Utilities#420 * Correct WORKFLOW.md audit flow and NUGET_USERNAME secret store by @ptr727 in ptr727/Utilities#422 * Describe the 5D audit as reporting defects, not failing by @ptr727 in ptr727/Utilities#424 * Promote develop to main by @ptr727 in ptr727/Utilities#423 * Spell out the up-to-date ruleset setting in the 5D audit summary by @ptr727 in ptr727/Utilities#425 * Promote develop to main by @ptr727 in ptr727/Utilities#426 * Bump DavidAnson/markdownlint-cli2-action from 24.0.0 to 24.1.0 in the actions-deps group by @dependabot[bot] in ptr727/Utilities#429 * Bump the nuget-deps group with 1 update by @dependabot[bot] in ptr727/Utilities#431 **Full Changelog**: ptr727/Utilities@4.0.18...4.0.28 Commits viewable in [compare view](ptr727/Utilities@4.0.18...4.0.28). </details> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions </details> Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
This was referenced Jul 21, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to #422, from Copilot review on the promotion PR #423.
AUDIT.mdis explicitly read-only: its secrets check is--
echo-based, with no defined non-zero exit contract. But twoWORKFLOW.mdsentences still said the audit "asserts" the names exist and "fail[s] if it cannot query them". That wording is a leftover from whenconfigure.sh checkperformed the audit and exited non-zero on drift; #422 moved the audit to AUDIT.md but left these two clauses describing the old behavior.Both now describe what AUDIT.md actually does: check the names, and report a missing name or a failed query as a defect. The App-installation sentence was adjusted for the same reason ("notes rather than fails" -> "notes rather than reports a defect").
Docs-only; no shipped input, so no release impact.