Repository navigation
Scan Diagnostics: daily NuGet scan with quarantine, catalog defaults and one living pull request - #69
Merged
Merged
Conversation
…ess load smoke test Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
… pull request; schemas; ScanDiagnostics action and workflow Work in progress of WP08 (#10): the modules, the action, the template workflow, the scan settings key, the scan-state schema, C14 for the scan state, the stub analyzer packages (compiled with the Roslyn of pwsh, so the assemblies carry their real names) and the NuGet, Extract and Catalog suites. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…pull request, Update schedule rewriter, Validate scan state Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…d 7.4, scan-mechanics), ADRs D45 and D46 Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…d, newly advertised ids, scan schedule kept when absent, stale pull request closed, NuGet input checks and retries - Invoke-DescriptorExtraction removes INPUT_*, GITHUB_TOKEN, GH_TOKEN, ACTIONS_*_TOKEN and every *TOKEN variable from the child's environment; action.yaml no longer passes GITHUB_TOKEN. - The plan records the checkout head; Publish-RulebookScan refuses a base branch that moved since (stage push). - Update-CatalogFromScan lists NewlyAdvertised (an advertised:false entry a stable version returns); the quarantine, title and body treat it like a new id. - ConvertTo-UpdatedWorkflowText keeps the shipped scan schedule when the scan key or scan.schedule is absent; only null removes it. - no-changes and direct-commit close an open scan pull request (Update-GitHubPullRequest -State closed). - Select-NuGetChannelVersion skips entries that are not versions; Save-NuGetPackage checks its paths; Get-NewPackageVersion only moves forward; Invoke-NuGetRequest retries 5xx, 429 and timeouts. - Static descriptor getters that throw are reported (fieldErrors), not swallowed; C7 annotations name the remedy. - Body: docs links as <url>, '@' in titles neutralised; Scan uses the tree and table helpers of Rulebook.Update. - Tests: missing-dependency and throwing-constructor stub faults, timeout kills the child, zip slip, retries, base move, stale PR close; CI checks the compiler titles from the resources. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…ped it at the console width) Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…redentials false, base-move guard warning, prerelease-first defaults and vanished ids, stale-PR line once, failure summary - The extraction child also loses GITHUB_ENV, GITHUB_PATH, GITHUB_OUTPUT, GITHUB_STATE, GITHUB_STEP_SUMMARY and every *_SECRET, *_PASSWORD, *_KEY, *_PAT variable, and runs in the work folder; the scan checkouts use persist-credentials: false. - A publish whose plan could not read the checkout HEAD warns that the base-move guard is inactive. - The first stable version of a prerelease-first id takes over its defaults without a defaultChanges element; a prerelease-only id is not vanished from a stable version. - A re-closed scan pull request carries the closing line once; an index with only invalid entries says so; a failed plan's summary is the failure message only; Get-ShortSha comes from Rulebook.Update. - CI: the compiler-title check only covers ids a package carries. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…x accepts CRLF Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
10 tasks
…ries (E2E step 5) One adopted id leaves both quarantine.default.json and quarantine.ci.json; the title said "2 quarantine entries released". It now counts distinct ids; the body keeps one row per stage. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…n; rescanning a channel Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…he token advice Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Arthurvdv
added a commit
to ALCops/rulebook
that referenced
this pull request
Oct 8, 2026
#5) Summary - New docs/quarantine.md for organization maintainers: what the daily Scan Diagnostics workflow does, choosing the quarantine policy with the exact abort message, reading its one living pull request (titles, sections with examples from the live run, record runs, why the branch is rebuilt and must not be pushed to), adopting a quarantined rule in a level file of your own with the endpoints regenerated in the same pull request, overrides that beat quarantine without releasing the entry, changed default severities and pinning, the catalog fields and flags and catalog/scan-state.json, running it by hand (includePrerelease, direct commit, commitOptions.createPullRequest, scan.schedule and the absent-key rule, rescanning a channel), troubleshooting. - docs/README.md: the planned new-rules.md row becomes the written quarantine.md row; docs/ghtokenworkflow.md and docs/updating.md each gain a sentence on the scan. - Behaviour described from the WP08 live run on Arthurvdv/rulebook-e2e-scan (2026-10-08) and the engine's docs/reference/scan-mechanics.md, merged in ALCops/rulebook-engine#69. Decisions WP08 (ALCops/rulebook-engine#10): D45 (one living pull request, record runs) and D46 (seeded ids are known; unadvertised, deprecated and vanished ids are catalog flags). Review Sonnet code-review, effort high, three rounds. Round 1: 15 findings (adoption example edited a shipped base/ file, stale endpoints after a hand edit, a closed pull request returning, push failure wording, housekeeping exception, overrides never release an entry, wording); one engine change followed (base moved reported plain). Round 2: 3 must-change items and 8 optional, all applied. Round 3: approve. Relates to ALCops/rulebook-engine#10 Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
ScanDiagnosticsand template workflowScanDiagnostics.yaml(daily viascan.schedule, shipped17 4 * * *): reads the newest stable and newer prerelease of the Development.Tools and ALCops.Analyzers packages, skips whatcatalog/scan-state.jsonrecorded, extracts every descriptor by reflection in a child pwsh per version, applies them to the catalog, quarantines new ids byquarantine.stages/prereleaseStages, releases adopted ids, regenerates and validates the endpoints, and publishes one living pull request onscan-diagnostics/<branch>(lease push, create or PATCH) or a direct commit.Rulebook.NuGet,Rulebook.Extract,Rulebook.Catalog(now ownsConvertTo-CatalogJson),Rulebook.Quarantine,Rulebook.Scan;Rulebook.GitHubgains PATCH,Find-GitHubPullRequestByHead,Update-GitHubPullRequest,Publish-GitHubChange -Force;Rulebook.Updaterewrites the schedule of both scheduled workflows and exportsGet-EffectiveDiffBlockand the tree and table helpers.scan.schedule; catalog schema scan fields; new closed schemarulebook-scan-state.schema.json; Validate checks the scan state (C14) and words C7 for its absence.tests/fixtures/stub-analyzers/); CI jobscan-actiondry-runs against nuget.org.docs/reference/scan-mechanics.md, naming, template content, update mechanics, README, CONTRIBUTING; ADRs D45 (one living pull request, record runs) and D46 (seeded ids known; unadvertised, deprecated, vanished as catalog flags).Decisions
WP08 planning interview of 2026-10-07 (D45, D46); the deviations from the issue text are listed in a comment on #10.
Review
Sonnet code-review, effort high, three rounds. Round 1: 11 findings (token inherited by the extraction child, base moved between plan and publish, unadvertised ids becoming advertised bypassed quarantine, absent scan key removed the schedule, stale PR after direct commit, unvalidated sole version, older index version counted as new, swallowed getter errors, test gaps, docs scope, hardening), all fixed in c6e64a0 and b85f14c. Round 2: approve, 3 recommended items (runner command files and checkout credentials reachable by the child, inactive base-move guard silent, CI title filter) and 7 optional, all applied in 50d2ccf. Round 3: approve, two minor notes folded in.
Closes #10
🤖 Generated with Claude Code