Skip to content

Scan Diagnostics: daily NuGet scan with quarantine, catalog defaults and one living pull request - #69

Merged
Arthurvdv merged 12 commits into
mainfrom
wp08/scan-diagnostics
Oct 8, 2026
Merged

Arthurvdv merged 12 commits into
mainfrom
wp08/scan-diagnostics

Conversation

@Arthurvdv

Copy link
Copy Markdown
Member

Summary

  • New action ScanDiagnostics and template workflow ScanDiagnostics.yaml (daily via scan.schedule, shipped 17 4 * * *): reads the newest stable and newer prerelease of the Development.Tools and ALCops.Analyzers packages, skips what catalog/scan-state.json recorded, extracts every descriptor by reflection in a child pwsh per version, applies them to the catalog, quarantines new ids by quarantine.stages / prereleaseStages, releases adopted ids, regenerates and validates the endpoints, and publishes one living pull request on scan-diagnostics/<branch> (lease push, create or PATCH) or a direct commit.
  • Modules Rulebook.NuGet, Rulebook.Extract, Rulebook.Catalog (now owns ConvertTo-CatalogJson), Rulebook.Quarantine, Rulebook.Scan; Rulebook.GitHub gains PATCH, Find-GitHubPullRequestByHead, Update-GitHubPullRequest, Publish-GitHubChange -Force; Rulebook.Update rewrites the schedule of both scheduled workflows and exports Get-EffectiveDiffBlock and the tree and table helpers.
  • Settings key scan.schedule; catalog schema scan fields; new closed schema rulebook-scan-state.schema.json; Validate checks the scan state (C14) and words C7 for its absence.
  • Offline suites on stub analyzer packages compiled at test time (tests/fixtures/stub-analyzers/); CI job scan-action dry-runs against nuget.org.
  • Docs: ARCHITECTURE §5.7 and §7.4, docs/reference/scan-mechanics.md, naming, template content, update mechanics, README, CONTRIBUTING; ADRs D45 (one living pull request, record runs) and D46 (seeded ids known; unadvertised, deprecated, vanished as catalog flags).

Decisions

WP08 planning interview of 2026-10-07 (D45, D46); the deviations from the issue text are listed in a comment on #10.

Review

Sonnet code-review, effort high, three rounds. Round 1: 11 findings (token inherited by the extraction child, base moved between plan and publish, unadvertised ids becoming advertised bypassed quarantine, absent scan key removed the schedule, stale PR after direct commit, unvalidated sole version, older index version counted as new, swallowed getter errors, test gaps, docs scope, hardening), all fixed in c6e64a0 and b85f14c. Round 2: approve, 3 recommended items (runner command files and checkout credentials reachable by the child, inactive base-move guard silent, CI title filter) and 7 optional, all applied in 50d2ccf. Round 3: approve, two minor notes folded in.

Closes #10

🤖 Generated with Claude Code

Arthurvdv and others added 9 commits October 7, 2026 21:00
…ess load smoke test

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
… pull request; schemas; ScanDiagnostics action and workflow

Work in progress of WP08 (#10): the modules, the action, the template workflow, the scan settings key, the
scan-state schema, C14 for the scan state, the stub analyzer packages (compiled with the Roslyn of pwsh, so the
assemblies carry their real names) and the NuGet, Extract and Catalog suites.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…pull request, Update schedule rewriter, Validate scan state

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…d 7.4, scan-mechanics), ADRs D45 and D46

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…d, newly advertised ids, scan schedule kept when absent, stale pull request closed, NuGet input checks and retries

- Invoke-DescriptorExtraction removes INPUT_*, GITHUB_TOKEN, GH_TOKEN, ACTIONS_*_TOKEN and every *TOKEN variable from the child's environment; action.yaml no longer passes GITHUB_TOKEN.
- The plan records the checkout head; Publish-RulebookScan refuses a base branch that moved since (stage push).
- Update-CatalogFromScan lists NewlyAdvertised (an advertised:false entry a stable version returns); the quarantine, title and body treat it like a new id.
- ConvertTo-UpdatedWorkflowText keeps the shipped scan schedule when the scan key or scan.schedule is absent; only null removes it.
- no-changes and direct-commit close an open scan pull request (Update-GitHubPullRequest -State closed).
- Select-NuGetChannelVersion skips entries that are not versions; Save-NuGetPackage checks its paths; Get-NewPackageVersion only moves forward; Invoke-NuGetRequest retries 5xx, 429 and timeouts.
- Static descriptor getters that throw are reported (fieldErrors), not swallowed; C7 annotations name the remedy.
- Body: docs links as <url>, '@' in titles neutralised; Scan uses the tree and table helpers of Rulebook.Update.
- Tests: missing-dependency and throwing-constructor stub faults, timeout kills the child, zip slip, retries, base move, stale PR close; CI checks the compiler titles from the resources.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…ped it at the console width)

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…redentials false, base-move guard warning, prerelease-first defaults and vanished ids, stale-PR line once, failure summary

- The extraction child also loses GITHUB_ENV, GITHUB_PATH, GITHUB_OUTPUT, GITHUB_STATE, GITHUB_STEP_SUMMARY and every *_SECRET, *_PASSWORD, *_KEY, *_PAT variable, and runs in the work folder; the scan checkouts use persist-credentials: false.
- A publish whose plan could not read the checkout HEAD warns that the base-move guard is inactive.
- The first stable version of a prerelease-first id takes over its defaults without a defaultChanges element; a prerelease-only id is not vanished from a stable version.
- A re-closed scan pull request carries the closing line once; an index with only invalid entries says so; a failed plan's summary is the failure message only; Get-ShortSha comes from Rulebook.Update.
- CI: the compiler-title check only covers ids a package carries.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…x accepts CRLF

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@Arthurvdv Arthurvdv added the enhancement New feature or request label Oct 7, 2026
@Arthurvdv Arthurvdv mentioned this pull request Oct 7, 2026
10 tasks
Arthurvdv and others added 3 commits October 8, 2026 11:20
…ries (E2E step 5)

One adopted id leaves both quarantine.default.json and quarantine.ci.json; the title said "2 quarantine entries
released". It now counts distinct ids; the body keeps one row per stage.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…n; rescanning a channel

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…he token advice

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@Arthurvdv
Arthurvdv merged commit f344934 into main Oct 8, 2026
5 checks passed
@Arthurvdv
Arthurvdv deleted the wp08/scan-diagnostics branch October 8, 2026 11:00
Arthurvdv added a commit to ALCops/rulebook that referenced this pull request Oct 8, 2026
#5)

Summary
- New docs/quarantine.md for organization maintainers: what the daily Scan Diagnostics workflow does, choosing the quarantine policy with the exact abort message, reading its one living pull request (titles, sections with examples from the live run, record runs, why the branch is rebuilt and must not be pushed to), adopting a quarantined rule in a level file of your own with the endpoints regenerated in the same pull request, overrides that beat quarantine without releasing the entry, changed default severities and pinning, the catalog fields and flags and catalog/scan-state.json, running it by hand (includePrerelease, direct commit, commitOptions.createPullRequest, scan.schedule and the absent-key rule, rescanning a channel), troubleshooting.
- docs/README.md: the planned new-rules.md row becomes the written quarantine.md row; docs/ghtokenworkflow.md and docs/updating.md each gain a sentence on the scan.
- Behaviour described from the WP08 live run on Arthurvdv/rulebook-e2e-scan (2026-10-08) and the engine's docs/reference/scan-mechanics.md, merged in ALCops/rulebook-engine#69.

Decisions
WP08 (ALCops/rulebook-engine#10): D45 (one living pull request, record runs) and D46 (seeded ids are known; unadvertised, deprecated and vanished ids are catalog flags).

Review
Sonnet code-review, effort high, three rounds. Round 1: 15 findings (adoption example edited a shipped base/ file, stale endpoints after a hand edit, a closed pull request returning, push failure wording, housekeeping exception, overrides never release an entry, wording); one engine change followed (base moved reported plain). Round 2: 3 must-change items and 8 optional, all applied. Round 3: approve.

Relates to ALCops/rulebook-engine#10

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

WP08: Diagnostic scan and quarantine

1 participant