Repository navigation
151 lines (124 loc) · 5.54 KB
/
Copy pathdotnet.yml
File metadata and controls
151 lines (124 loc) · 5.54 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
# Build, test and pack on every push to main and every PR.
#
# Linux only, as in the sibling repositories: the shipping code is pure managed code on a single
# TFM, and a second runner would re-test the .NET runtime rather than this library.
#
# Actions are pinned to commit SHAs, not tags: a tag can be moved to a different commit (the
# tj-actions/changed-files compromise, March 2025), a SHA cannot. The trailing `# vX.Y.Z` is what
# Dependabot reads to propose updates, so keep it next to the SHA.
#
# The SDK comes from global.json, not from a version typed here, so CI builds with exactly the
# band the repository pins.
#
# Every job runs with no Metalama license on the machine, so a green run is the standing evidence
# that consumers need none either. It was first measured in a clean container on 2026-09-27
# (spikes/FabricSpike, finding 9): the whole solution builds and the woven probes pass.
name: .NET
on:
push:
branches: [ "main" ]
pull_request:
branches: [ "main" ]
workflow_dispatch:
permissions:
contents: read
defaults:
run:
shell: bash
# A new push to a PR makes the in-flight run pointless; main is never cancelled.
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
env:
DOTNET_NOLOGO: true
DOTNET_CLI_TELEMETRY_OPTOUT: true
DOTNET_SKIP_FIRST_TIME_EXPERIENCE: true
jobs:
test:
name: Test (ubuntu-latest)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
- name: Setup .NET
uses: actions/setup-dotnet@26b0ec14cb23fa6904739307f278c14f94c95bf1 # v5.4.0
with:
global-json-file: global.json
- name: Restore
run: dotnet restore CodoMetis.TypeKit.slnx
- name: Build
run: dotnet build CodoMetis.TypeKit.slnx -c Release --no-restore
# The EF Core round trips start a PostgreSQL container; ubuntu runners have Docker.
- name: Test
run: >
dotnet test --solution CodoMetis.TypeKit.slnx -c Release --no-build
--report-xunit-trx --results-directory TestResults
- name: Upload test results
uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6.0.0
if: always()
with:
name: test-results
path: TestResults/**/*.trx
if-no-files-found: ignore
pack:
name: Pack
runs-on: ubuntu-latest
needs: test
steps:
- uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
- name: Setup .NET
uses: actions/setup-dotnet@26b0ec14cb23fa6904739307f278c14f94c95bf1 # v5.4.0
with:
global-json-file: global.json
# Packing is itself a check: a package that names a README it does not pack fails here.
- name: Build
run: dotnet build CodoMetis.TypeKit.slnx -c Release
- name: Pack
run: dotnet pack CodoMetis.TypeKit.slnx -c Release --no-build -o dist
# The smoke test publishes a consumer with Native AOT, which links with the platform's clang
# and zlib (docs/plan.md §11).
- name: Native AOT prerequisites
run: sudo apt-get update && sudo apt-get install -y --no-install-recommends clang zlib1g-dev
# Against the packed feed, exactly as the release workflow runs it. The `consumer` job runs the
# other mode, packing its own feed. The two are not interchangeable: packing fills the private
# package cache with the solution's dependencies, and a restore that only works because of that
# passes one way and fails the other, which broke a release in a sibling repository.
- name: Consumer smoke test against the packed feed
run: ./test/consumer-smoke-test.sh dist
# Here as well as in the release, so a broken SBOM step surfaces on a PR rather than on release
# day. The flags are the release workflow's; ReleaseWiringTests keeps the exclusions in step.
- name: Generate SBOMs
run: |
dotnet tool restore
version="$(dotnet msbuild src/CodoMetis.TypeKit/CodoMetis.TypeKit.csproj -getProperty:Version)"
for directory in src/*/; do
id="$(basename "$directory")"
dotnet cyclonedx "$directory$id.csproj" \
--output dist --filename "$id.$version.cdx.json" --output-format Json \
--set-type Library --set-nuget-purl --set-name "$id" --set-version "$version" \
--include-project-references \
--exclude-filter Microsoft.CodeAnalysis.CSharp,Microsoft.CodeAnalysis.Analyzers,Microsoft.NET.ILLink.Tasks,NETStandard.Library
done
- name: Upload packages
uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6.0.0
with:
name: nupkg
path: |
dist/*.nupkg
dist/*.snupkg
dist/*.cdx.json
consumer:
name: Consumer smoke test
runs-on: ubuntu-latest
needs: test
steps:
- uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
- name: Setup .NET
uses: actions/setup-dotnet@26b0ec14cb23fa6904739307f278c14f94c95bf1 # v5.4.0
with:
global-json-file: global.json
# The smoke test publishes a consumer with Native AOT, which links with the platform's clang
# and zlib (docs/plan.md §11).
- name: Native AOT prerequisites
run: sudo apt-get update && sudo apt-get install -y --no-install-recommends clang zlib1g-dev
- name: Consumer smoke test, packing its own feed
run: ./test/consumer-smoke-test.sh