Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
72 changes: 66 additions & 6 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -1,27 +1,87 @@
# Weekly dependency PRs. NuGet versions live in each csproj (no central package
# management), so Dependabot walks the whole tree rather than a manifest folder.
version: 2

updates:
# ---------------------------------------------------------------------------
# NuGet packages (src + tests + demo)
#
# Minor and patch bumps are grouped into a single PR so the auto-merge
# workflow has one unambiguous update-type to act on. Major bumps are
# deliberately left OUT of the group, so each arrives as its own PR and
# stays open for manual review.
# ---------------------------------------------------------------------------
- package-ecosystem: nuget
directory: "/"
schedule:
interval: weekly
day: monday
open-pull-requests-limit: 5
time: "06:00"
timezone: Etc/UTC
open-pull-requests-limit: 10
commit-message:
prefix: "Bump"
prefix: "chore(deps)"
labels:
- dependencies
- nuget
# -------------------------------------------------------------------------
# These two carry deliberate per-TFM floors (see the csproj comment): a
# net8.0 consumer must stay on its own 8.0.x servicing line, so an
# 8.x -> 10.x major PR is never mergeable and would just be weekly noise.
#
# The list is exactly this repo's per-TFM floors and nothing else
# (STANDARD.md 4.10). Auth additionally floors
# System.Security.Cryptography.ProtectedData; this package does not
# reference it, so naming it here would assert a dependency that is not in
# the tree.
#
# Two caveats, both inherent to Dependabot rather than to this repo:
# 1. `ignore` matches by dependency NAME and cannot be scoped to a single
# target framework. These packages are referenced under BOTH the net8.0
# and net10.0 ItemGroups, so this also suppresses a future net10 major
# (10.x -> 11.x). Bump those by hand when a new .NET major lands.
# 2. `ignore` conditions filter SECURITY updates as well as version
# updates, so a major-version security fix for these would also be
# suppressed. Low risk in practice (a CVE fix for 8.0.x ships as
# 8.0.y, a patch), but worth knowing.
# -------------------------------------------------------------------------
ignore:
- dependency-name: Microsoft.Extensions.DependencyInjection.Abstractions
update-types:
- version-update:semver-major
- dependency-name: Microsoft.Extensions.Http
update-types:
- version-update:semver-major
groups:
nuget-minor-patch:
patterns:
- "*"
update-types:
- minor
- patch

# ---------------------------------------------------------------------------
# GitHub Actions across all three workflows: checkout, setup-dotnet, cache,
# upload/download-artifact and NuGet/login in ci.yml, codeql-action in
# codeql.yml, fetch-metadata in dependabot-auto-merge.yml. Same grouping rule
# as NuGet. This is also what keeps action versions uniform across the estate
# (STANDARD.md 3.9).
# ---------------------------------------------------------------------------
- package-ecosystem: github-actions
directory: "/"
schedule:
interval: weekly
day: monday
open-pull-requests-limit: 5
time: "06:00"
timezone: Etc/UTC
open-pull-requests-limit: 10
commit-message:
prefix: "Bump"
prefix: "chore(actions)"
labels:
- dependencies
- github-actions
groups:
actions-minor-patch:
patterns:
- "*"
update-types:
- minor
- patch
143 changes: 119 additions & 24 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
@@ -1,34 +1,65 @@
# CI for NextIteration.SpectreConsole.SelfUpdate.
# Canonical shape defined in NextIteration.Standards STANDARD.md section 3 — change it
# there first, then here.
#
# The single required status check is `ci`, the aggregating gate below. `build` and `test`
# must NOT be required directly: `test` is a matrix, so its check names carry the matrix
# values and change whenever the matrix does. The gate's name is stable.
#
# This file absorbed the former release.yml (STANDARD.md 3.0). The `publish` job now
# downloads the artifact this run's `build` job produced, so the bytes pushed to
# nuget.org are the exact bytes the gate saw. release.yml had to rebuild from the tag,
# publishing an artifact no gate had ever tested.
#
# nuget.org Trusted Publishing binds its policy to a specific workflow FILE. The policy
# for this package was repointed from release.yml to ci.yml as part of that fold; if
# publishing ever fails to authenticate, check that first.
#
# The test matrix runs all three platforms (STANDARD.md 3.1.1), and here that is not a
# formality: the library resolves an OS/arch RID token, picks a per-OS cache directory
# (AppData, ~/Library/Caches, XDG_CACHE_HOME), replaces a running executable, and takes
# an exclusive install lock whose FileShare.None semantics differ between POSIX and
# Windows. One test is deliberately POSIX-only and returns early on Windows — see the
# comment on InstallLockTests.Acquire_when_directory_not_writable_throws_not_writable.
name: CI

env:
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true

# Build + test + pack on every push to main and every PR. Tag pushes are
# handled by .github/workflows/release.yml — that workflow runs the same
# build/test plus publishes to nuget.org.
on:
push:
branches: [ main ]
tags: [ 'v*' ]
pull_request:
branches: [ main ]

# Superseded pushes are cancelled. Tag builds are never cancelled — a half-cancelled
# release can leave an incomplete package set on nuget.org.
concurrency:
group: ci-${{ github.ref }}
cancel-in-progress: ${{ !startsWith(github.ref, 'refs/tags/') }}

permissions:
contents: read

jobs:
build:
runs-on: ubuntu-latest

timeout-minutes: 15
steps:
- name: Checkout
uses: actions/checkout@v7
- uses: actions/checkout@v7

- name: Setup .NET
uses: actions/setup-dotnet@v6
# Both SDKs: the shipping project targets net8.0 and net10.0 and the tests run
# against BOTH (STANDARD.md 2.3), which needs the 8.0 runtime present.
- uses: actions/setup-dotnet@v6
with:
# 8.0.x provides the runtime the net8.0 test leg executes on; the
# 10.0.x SDK does the building for both targets.
dotnet-version: |
8.0.x
10.0.x

- uses: actions/cache@v6
with:
path: ~/.nuget/packages
key: nuget-${{ runner.os }}-${{ hashFiles('**/Directory.Packages.props', '**/*.csproj') }}
restore-keys: nuget-${{ runner.os }}-

- name: Restore
run: dotnet restore

Expand All @@ -42,27 +73,91 @@ jobs:
uses: actions/upload-artifact@v7
with:
name: nuget-package
path: ./artifacts/*.nupkg
# Both .nupkg and .snupkg, so the publish job's glob also pushes symbols.
# release.yml globbed *.nupkg only and silently never published symbols.
path: ./artifacts/*nupkg

test:
strategy:
fail-fast: false # one platform failing must not hide another's result
matrix:
os: [ ubuntu-latest, macos-latest, windows-latest ]
fail-fast: false
os: [ ubuntu-latest, windows-latest, macos-latest ]
runs-on: ${{ matrix.os }}

timeout-minutes: 20
steps:
- name: Checkout
uses: actions/checkout@v7
- uses: actions/checkout@v7

- name: Setup .NET
uses: actions/setup-dotnet@v6
- uses: actions/setup-dotnet@v6
with:
# 8.0.x provides the runtime the net8.0 test leg executes on; the
# 10.0.x SDK does the building for both targets.
dotnet-version: |
8.0.x
10.0.x

- uses: actions/cache@v6
with:
path: ~/.nuget/packages
key: nuget-${{ runner.os }}-${{ hashFiles('**/Directory.Packages.props', '**/*.csproj') }}
restore-keys: nuget-${{ runner.os }}-

# Tests run across every shipped TFM (STANDARD.md 2.3). No --no-build: this job
# does not share a filesystem with `build`, and rebuilding is cheaper and less
# fragile than shipping obj/ between jobs.
- name: Test
run: dotnet test --configuration Release
run: dotnet test --configuration Release --verbosity normal

# THE required status check. Aggregates everything above so the ruleset never has to
# know the matrix shape. `if: always()` is essential — without it the gate is skipped
# when a dependency fails, and a skipped check reads as success to branch protection.
ci:
needs: [ build, test ]
if: always()
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- name: Verify every required job succeeded
env:
RESULTS: ${{ join(needs.*.result, ',') }}
run: |
echo "upstream results: $RESULTS"
case "$RESULTS" in
*failure*|*cancelled*|*skipped*)
echo "::error title=CI gate::an upstream job did not succeed ($RESULTS)"
exit 1 ;;
esac
echo "all upstream jobs succeeded"

publish:
needs: ci
runs-on: ubuntu-latest
timeout-minutes: 15
if: startsWith(github.ref, 'refs/tags/')

permissions:
id-token: write # GitHub OIDC token issuance for NuGet trusted publishing
contents: read

steps:
- uses: actions/setup-dotnet@v6
with:
dotnet-version: '10.0.x'

- uses: actions/download-artifact@v8
with:
name: nuget-package
path: ./artifacts

# Exchanges the OIDC token for a short-lived (1h) nuget.org key. Requires a
# Trusted Publishing policy on nuget.org bound to this repo + THIS workflow file.
# NUGET_USER is the nuget.org account name, not an email.
- name: NuGet login (OIDC to temporary API key)
uses: NuGet/login@v1
id: login
with:
user: ${{ secrets.NUGET_USER }}

- name: Publish to NuGet
run: >
dotnet nuget push "./artifacts/*.nupkg"
--api-key "${{ steps.login.outputs.NUGET_API_KEY }}"
--source https://api.nuget.org/v3/index.json
--skip-duplicate
62 changes: 62 additions & 0 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,62 @@
# CodeQL code scanning. See STANDARD.md section 4.4.
name: CodeQL

on:
push:
branches: [ main ]
pull_request:
branches: [ main ]
schedule:
# Weekly, so a newly published query pack finds existing code even when
# nothing has been pushed. Offset off the hour to avoid the scheduling spike.
- cron: '37 4 * * 1'

concurrency:
group: codeql-${{ github.ref }}
cancel-in-progress: true

permissions:
contents: read

jobs:
analyze:
name: analyze
runs-on: ubuntu-latest
timeout-minutes: 30

permissions:
security-events: write # required to upload results
contents: read

steps:
- name: Checkout
uses: actions/checkout@v7

- name: Setup .NET
uses: actions/setup-dotnet@v6
with:
dotnet-version: |
8.0.x
10.0.x

- name: Initialize CodeQL
uses: github/codeql-action/init@v4
with:
languages: csharp
# security-and-quality is broader than the default security-extended;
# these are small libraries, so the extra findings are affordable.
queries: security-and-quality

# Explicit build rather than autobuild: these repos multi-target, and
# autobuild has picked a single TFM in the past, silently analysing half
# the code. Restore is separate so a restore failure is legible.
- name: Restore
run: dotnet restore

- name: Build
run: dotnet build --configuration Release --no-restore

- name: Perform CodeQL analysis
uses: github/codeql-action/analyze@v4
with:
category: "/language:csharp"
Loading