Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .bot/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,4 +7,4 @@ This folder is reserved for local-only AI working material such as:
- design alternatives
- temporary agent state

Keep this folder out of source control. Move only finalized, non-confidential guidance into `AGENTS.md` or `.github/copilot-instructions.md`.
The `.bot/README.md` file itself is intentionally tracked in source control. All other `.bot/` working material remains local-only and excluded from source control. Move only finalized, non-confidential guidance into `AGENTS.md` or `.github/copilot-instructions.md`.
22 changes: 20 additions & 2 deletions .github/CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -75,9 +75,27 @@ Package-specific release notes live under `.nuget/<ProjectName>/PackageReleaseNo

After PR validation and merge, a maintainer creates and pushes a `vX.Y.Z` tag (or `vX.Y.Z-prerelease`, without build metadata) for the intended commit in `main` history. The tag push starts `release.yml`, which checks the tag identity and ancestry, builds signed Release packages from that commit, validates their versions and existing NuGet content, and sends the validated package artifact to the protected `Production` publication job.

After NuGet publication, the workflow runs post-release tests and analysis and builds the multi-platform DocFX OCI image from the same commit. The verified archive and SHA-256 checksum are attached to a draft GitHub Release before that release is published. Post-release assurance failures do not roll back published packages; inspect the release summary and resolve failures against its recorded commit.
After NuGet publication, the workflow runs post-release tests and analysis and builds the multi-platform DocFX OCI image from the same commit. The verified archive and SHA-256 checksum are attached to a draft GitHub Release using its numeric release ID. The workflow leaves the release as a draft. A maintainer reviews/edits the release and assurance results, then presses **Publish** to declare it deployable. Post-release assurance failures do not roll back published packages; inspect the release summary and resolve failures against its recorded commit.

A published GitHub Release starts `deploy.yml`. To retry deployment, dispatch that workflow from `main` with the existing published release tag. Deployment requires the versioned OCI archive and checksum, resolves the tag to its source commit, and promotes the verified image to JCR through `Production` without rebuilding it. The workflow reports the immutable image digest for a Kubernetes handoff; this repository does not perform the Kubernetes rollout.
The Git tag identifies the release; `main` identifies repository health; the released SHA ties them together. Release assurance calls the same reusable workflows as `pr.yml`: `jobs-sonarcloud@v3`, `jobs-codecov@v1`, and `jobs-codeql@v3`. Assurance always checks out the exact released tag's commit using each workflow's `ref` input, even if `main` has advanced. SonarCloud explicitly reports `sonar.branch.name=main`, the released SemVer as project version, and the released SHA as SCM revision through the existing `parameters` input, retaining the scanner's default exclusions. Codecov explicitly reports `branch: main` and `commit: <released SHA>` independently of its checkout `ref`. CodeQL uses `analysis-ref: refs/heads/main` and `analysis-sha: <released SHA>`, forwarded to the finalize action's `ref` and `sha` inputs. SonarCloud and CodeQL request Release builds; callers that omit configuration retain Debug builds. Release tags must never become analysis branches.

Before accepting assurance, verify service records rather than relying on successful Actions jobs: SonarCloud's `api/project_analyses/search?project=Cuemon&branch=main` must contain the released `revision` and `projectVersion`; Codecov's `api/v2/github/codebeltnet/repos/cuemon/commits/<released SHA>/` must report `branch: main` and the expected `commitid`; GitHub's `repos/codebeltnet/cuemon/code-scanning/analyses?tool_name=CodeQL&ref=refs%2Fheads%2Fmain` must contain the expected `commit_sha`. For `v10.8.0`, every check must identify `33e6e756984e5d21a4d0e6b9171d417a58a779f1` on the canonical main branch. Any assurance replay must use these same identities and the exact released SHA; rerunning a historical job does not pick up corrected workflow parameters.

If OCI asset attachment fails after NuGet publication and the OCI build succeeded, dispatch `release.yml` from **main** with `recovery: assets` (the default), the existing `tag` and original `source_run_id`. This mode never rebuilds packages/images, invokes NuGet publication, reruns assurance, creates a replacement release, or publishes the draft. Missing, expired or unverifiable artifacts cause failure with diagnostics rather than replacement bytes.

To correct or replay repository-health telemetry, dispatch the corrected workflow from **main** with `recovery: assurance`, the existing release `tag`, and its original tag-push `source_run_id`. Preflight confirms the source run's successful tag validation and NuGet publication, resolves the unchanged tag, and checks its membership in main history. This mode regenerates tests/coverage and all three analyses from that exact released SHA. It does not require the original OCI artifacts or alter NuGet packages, OCI assets, the GitHub Release, or deployment. A service-record verification job waits for processing, then fails unless SonarCloud reports main with the released SHA and SemVer, Codecov reports main with that SHA, and CodeQL records refs/heads/main with that SHA. Assurance recovery fails when tests, analysis, or service verification fail.

Publish the backward-compatible `codecov-scan@v1` and `codeql-scan-finalize@v1` extensions, then `jobs-codecov@v1`, `jobs-sonarcloud@v3`, and `jobs-codeql@v3`, before publishing the Cuemon workflow that uses their new inputs. For the existing release, the recovery request is:

```powershell
gh workflow run release.yml --repo codebeltnet/cuemon --ref main -f recovery=assurance -f tag=v10.8.0 -f source_run_id=37153698543
```

This command requires the corrected workflow and wrappers to be available remotely. Checkout and all service verification must identify `main @ 33e6e756984e5d21a4d0e6b9171d417a58a779f1`; the current tip of main is only the orchestration source.

Recovery verifies the artifact's download digest, archive checksum, OCI version/revision and `linux/amd64`/`linux/arm64` coverage before attachment. Exact existing release assets are accepted; conflicting bytes fail before mutation, and only missing assets are uploaded. Recovery can be dispatched again after a partial upload. Fix orchestration on main and resume from the last durable successful boundary; do not replay immutable publication because later finalization failed. Actions artifacts are retained for 30 days, so recover while the source artifact is available.

A human-published GitHub Release starts `deploy.yml`. To retry deployment, dispatch that workflow from `main` with the existing published release tag. Deployment requires the versioned OCI archive and checksum, resolves the tag to its source commit, and promotes the verified image to JCR through `Production` without rebuilding it. Publishing the GitHub Release and approving the Production environment are separate human decisions. The workflow reports the immutable image digest for a Kubernetes handoff; this repository does not perform the Kubernetes rollout.

If publication fails, inspect the job results before retrying. A partially completed NuGet push may already have published some packages; rerun the failed publication job to reuse its validated artifact. Keep release tags fixed: publication rechecks the live tag against the built commit and rejects a mismatch.

Expand Down
Loading
Loading