Repository navigation
ci: land the SHA pins, Dependabot and the consumer smoke test on main (recovers #5, #9) - #13
Merged
Merged
Conversation
Every action in both workflows was referenced by major tag. A tag can be moved to a different commit — that is how the tj-actions/changed-files compromise (March 2025) reached every workflow that trusted `@v45` — and NuGet/login runs in the one job that can mint a publishing token. Each reference is now the commit SHA of the current release, with the exact tag in a trailing comment (checkout v6.1.0, setup-dotnet v5.4.0, upload-artifact v6.0.0, download-artifact v7.0.0, NuGet/login v1.2.0), which is what Dependabot reads to propose an update. .github/dependabot.yml keeps the pins current: github-actions weekly, one grouped PR. It also covers the test projects' NuGet references monthly, and deliberately not src/ — the provider and NodaTime references there are the floors consumers restore against, and raising one is a release decision. The test projects' EF Core and Npgsql references track those floors and are ignored for the same reason. Security advisories still surface for everything through Dependabot security updates and NuGetAudit. Verified: SHAs resolved from each repository's peeled tag refs; actionlint clean on both workflows; dependabot.yml parses; the conventions suite passes. Co-Authored-By: Claude Fable 5 <[email protected]>
Every layer of the suite references the projects directly. A ProjectReference hides exactly what breaks for a consumer of the package: a satellite whose nuspec fails to declare the core package, a version range that lets NuGet resolve a different core than the one built here, a type public in the project and missing from the package, a plugin that registers through a project reference and not through the assembly a consumer restores. Each packs cleanly and restores cleanly, and the first person to notice is a consumer. test/consumer-smoke-test.sh packs the four packages, restores them into throwaway projects created outside the repository — inside it, Directory.Build.props would apply and they would stop resembling anything a consumer builds — compiles real code against them, runs it, and asserts on what it prints and on the SQL the EF plugins translate. Never on the exit code alone. Two consumers: core only (parse, algebra, JSON round trip, value set canonical form), and the NodaTime EF satellite, which pulls all four through the nuspec chain — the chain itself is asserted from `dotnet list package --include-transitive`, each id at this version — and translates a BCL range, a NodaTime range and a value set predicate to SQL through ToQueryString, which never connects. Two things carried over from the sibling repository because they were learned the hard way there: NUGET_PACKAGES redirected to a private folder, since NuGet resolves id+version from the global cache before any source and a locally built package is otherwise shadowed by whatever build of that version was restored before; and package source mapping in the generated nuget.config, so this repository's ids come from the local feed only and everything else from nuget.org — restricting the whole restore to the local feed fails with NU1101 on the transitive dependencies. Wired into both workflows in both invocation modes: a `consumer` job on every PR that packs its own feed, and a step in the pack job and in the release gate that is handed the pre-built dist — the artifacts published are the artifacts tested. The script builds before it packs, so it works whether or not GeneratePackageOnBuild is set. Verified: passes in both modes locally. Sabotaging the mechanism — the NodaTime satellite no longer calling UseValueRanges() — fails the run. actionlint clean. Co-Authored-By: Claude Fable 5 <[email protected]>
test: add a consumer smoke test that exercises delivery, not code
…recover/pins-dependabot-smoke-test # Conflicts: # CLAUDE.md
Owner
Author
|
Added one commit: Dependabot ignores semver-major action bumps (same rule as EFCore.ComplexIndexes #25 — Dependabot's first PR there proposed download-artifact v8, which stops auto-unzipping and would break the publish job's |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
#5 (SHA-pinned actions + Dependabot) and #9 (consumer smoke test) were stacked PRs. They were merged into their base branches seconds after those bases had already been merged to
main, so their content never reachedmain—maintoday has no.github/dependabot.yml, notest/consumer-smoke-test.sh, and the actions are still tag-pinned. My stacking set that trap; this lands the content.What
origin/main+ the orphanedci/pin-actions-dependabotbranch (which contains #5 and #9), one conflict resolved in CLAUDE.md (the conventions-project bullet #6 reworded, with the smoke-test bullet #9 added after it). Everything else merged cleanly. Nothing new beyond what #5 and #9 already described and verified:uses:SHA-pinned with the exact tag in a trailing comment;.github/dependabot.yml(actions weekly, nuget monthly ontest/*, EF/Npgsql ignored);test/consumer-smoke-test.sh+ theConsumer smoke testjob on PRs and the pre-built-feed step in Pack and in the release gate.actionlintclean; conventions suite green. Once merged,Consumer smoke testis a candidate required check.🤖 Generated with Claude Code