V10.8.0/post ci fix - #173
Merged
Merged
Conversation
Allow maintainers to resume OCI asset attachment from the original verified artifact after NuGet publication. Keep recovery from rebuilding or republishing immutable products, and leave GitHub Release publication as a human decision.
Explain how maintainers review draft releases and recover OCI asset attachment from the original Actions artifact. This keeps the human publication decision and separate deployment approval clear.
Make clear that the README is intentionally tracked while other bot working material stays local. This prevents the directory guidance from contradicting the repository contents.
Limit the temporary artifact restrictions to files created by DocFX maintenance. This preserves the documentation workflow safeguards without presenting them as repository-wide file rules.
Let maintainers replay post-release tests and repository-health analyses against the exact released SHA after correcting workflow telemetry. Verify that SonarCloud, Codecov and CodeQL record the canonical main identity before treating the replay as successful.
Document the reporting branch and commit identities required for release assurance, plus the recovery dispatch maintainers can use to replay checks against the released SHA.
|
Allow asset recovery to restore a missing draft release and search paginated SonarCloud analyses for the released revision. This keeps recovery reliable after release edits or newer main analyses.
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #173 +/- ##
==========================================
+ Coverage 90.06% 94.18% +4.11%
==========================================
Files 606 605 -1
Lines 12884 19089 +6205
Branches 1819 1831 +12
==========================================
+ Hits 11604 17979 +6375
- Misses 781 1083 +302
+ Partials 499 27 -472 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This pull request makes release finalization recoverable and verifies that post-release assurance is recorded against the released commit on the canonical main branch. It adds separate recovery paths for OCI asset attachment and assurance replay, while keeping GitHub Release publication under maintainer control.
Release recovery:
Assurance identity:
mainand CodeQL results onrefs/heads/main, all tied to the released SHA.Repository guidance: