Skip to content
Merged
Show file tree
Hide file tree
Changes from 2 commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 10 additions & 3 deletions .github/workflows/nuget-online-convergence.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ permissions:

jobs:
verify-convergence:
if: github.event.workflow_run.conclusion == 'success' && github.event.workflow_run.head_repository.full_name == github.repository && github.event.workflow_run.event == 'push'
if: github.event.workflow_run.conclusion == 'success' && github.event.workflow_run.head_repository.full_name == github.repository
runs-on: ubuntu-latest
permissions:
contents: read
Expand All @@ -31,13 +31,20 @@ jobs:
ref: ${{ github.event.repository.default_branch }}
persist-credentials: false

- name: Download release metadata artifact
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4
with:
run-id: ${{ github.event.workflow_run.id }}
github-token: ${{ github.token }}
name: release-meta
path: artifacts/ci/nuget-online-convergence/release-meta/

- name: Resolve release metadata
id: meta
env:
RELEASE_TAG: ${{ github.event.workflow_run.head_branch }}
RELEASE_RUN_URL: ${{ github.event.workflow_run.html_url }}
shell: bash
run: bash tools/ci/release/resolve_workflow_run_release_meta.sh "${RELEASE_TAG}" "${RELEASE_RUN_URL}"
run: bash tools/ci/release/resolve_workflow_run_release_meta.sh artifacts/ci/nuget-online-convergence/release-meta/release-meta.json "${RELEASE_RUN_URL}"

- name: Verify NuGet online convergence (all endpoints required)
shell: bash
Expand Down
49 changes: 49 additions & 0 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -87,6 +87,9 @@ jobs:
- name: Source-based tests
run: dotnet test tests/FileTypeDetectionLib.Tests/FileTypeDetectionLib.Tests.csproj -c Release --no-build -v minimal

Comment thread
tomtastisch marked this conversation as resolved.
- name: Fuzz tests (release blocker)
run: bash tools/ci/release/run_fuzz_release_gate.sh tests/FileTypeDetectionLib.Tests/FileTypeDetectionLib.Tests.csproj

- name: API contract tests
run: dotnet test tests/FileTypeDetectionLib.Tests/FileTypeDetectionLib.Tests.csproj -c Release --no-build --filter "Category=ApiContract" -v minimal

Expand Down Expand Up @@ -126,6 +129,17 @@ jobs:
path: artifacts/nuget/naming-snt-summary.json
if-no-files-found: error

- name: Prepare release metadata artifact
shell: bash
run: bash tools/ci/release/write_release_meta_artifact.sh "${{ steps.tag.outputs.tag }}" "${{ steps.tag.outputs.version }}" "https://github.com/${{ github.repository }}/actions/runs/${{ github.run_id }}" "artifacts/release-meta/release-meta.json"

- name: Upload release metadata artifact
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
with:
name: release-meta
path: artifacts/release-meta/release-meta.json
if-no-files-found: error

publish-nuget:
runs-on: ubuntu-latest
needs: version-policy
Expand Down Expand Up @@ -233,3 +247,38 @@ jobs:
env:
RELEASE_TAG: ${{ github.event_name == 'workflow_dispatch' && github.event.inputs.release_tag || github.ref_name }}
run: bash tools/ci/release/gate4_verify_postpublish.sh "${RELEASE_TAG#v}" "${{ steps.nupkg.outputs.path }}"

enforce-online-convergence:
runs-on: ubuntu-latest
needs: publish-nuget
if: (github.event_name == 'push' && startsWith(github.ref, 'refs/tags/v')) || github.event_name == 'workflow_dispatch'
permissions:
contents: read
steps:
- name: Checkout
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4

- name: Download release metadata artifact
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4
with:
name: release-meta
path: artifacts/release-meta/

- name: Resolve release metadata
id: meta
env:
RELEASE_RUN_URL: https://github.com/${{ github.repository }}/actions/runs/${{ github.run_id }}
shell: bash
run: bash tools/ci/release/resolve_workflow_run_release_meta.sh artifacts/release-meta/release-meta.json "${RELEASE_RUN_URL}"

- name: Verify NuGet online convergence (all endpoints required)
shell: bash
run: bash tools/ci/release/verify_nuget_online_convergence.sh "${{ steps.meta.outputs.release_version }}" "${{ steps.meta.outputs.verify_log_path }}" "${{ steps.meta.outputs.package_id }}"

- name: Upload convergence artifact
if: always()
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
with:
name: nuget-online-convergence-sync
path: artifacts/ci/nuget-online-convergence/
if-no-files-found: error
2 changes: 1 addition & 1 deletion Directory.Build.props
Original file line number Diff line number Diff line change
Expand Up @@ -26,6 +26,6 @@
Condition="Exists('$(MSBuildThisFileDirectory)tools/analyzers/BannedSymbols.txt')" />
</ItemGroup>
<PropertyGroup>
<RepoVersion>6.1.13</RepoVersion>
<RepoVersion>6.1.14</RepoVersion>
</PropertyGroup>
</Project>
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@ Diese Datei mappt die repo-/governance-basierten Scorecard-Alerts ohne konkrete
| `BranchProtectionID` | `main` nur via PR + required checks | Branch Protection/Ruleset aktiv, required checks konfiguriert | `gh api repos/tomtastisch/FileClassifier/branches/main/protection` | `required_status_checks` vorhanden | direkter Push auf `main` technisch blockiert |
| `CodeReviewID` | Mindestens 1 PR-Review vor Merge | PR-Review-Policy in Branch Protection/Ruleset | `gh api repos/tomtastisch/FileClassifier/branches/main/protection --jq '.required_pull_request_reviews'` | `required_approving_review_count >= 1` | Merge ohne Review nicht möglich |
| `MaintainedID` | Nachweis aktiver Wartung | Kontinuierliche Commits/Releases + aktive CI | `gh api repos/tomtastisch/FileClassifier/commits?per_page=20` und `gh api repos/tomtastisch/FileClassifier/actions/runs?per_page=20` | in den letzten 90 Tagen Commits vorhanden | in den letzten 30 Tagen erfolgreiche Workflow-Runs vorhanden |
| `FuzzingID` | Fuzzing-Baseline vorhanden (mind. report-only) | Workflow `.github/workflows/fuzzing-baseline.yml` | `gh workflow view fuzzing-baseline.yml --yaml` und `gh run list --workflow fuzzing-baseline.yml --limit 10` | Workflow existiert und ist ausführbar | mindestens ein erfolgreicher Run in den letzten 30 Tagen |
| `FuzzingID` | Fuzzing-Baseline vorhanden (zusätzlich als Release-Blocker aktiviert) | Workflow `.github/workflows/fuzzing-baseline.yml` | `gh workflow view fuzzing-baseline.yml --yaml` und `gh run list --workflow fuzzing-baseline.yml --limit 10` | Workflow existiert und ist ausführbar | mindestens ein erfolgreicher Run in den letzten 30 Tagen |
| `CIIBestPracticesID` | Prozess-/Security-Baseline dokumentiert und nachvollziehbar | Audit-/Governance-Docs + CI-Evidence + Security Policy | `ls docs/audit` + `bash tools/audit/verify-security-claims.sh` | Audit-Index vorhanden und verlinkt | Security-Claims-Evidence liefert `pass` für Blocker-Claims |

## Hinweis zur Scorecard-Interpretation
Expand Down
3 changes: 2 additions & 1 deletion docs/0_de/ci/002_NUGET_TRUSTED_PUBLISHING.MD
Original file line number Diff line number Diff line change
Expand Up @@ -33,8 +33,9 @@ Die aktive Trusted-Publishing-Policy ist an folgende Identität gebunden:
- Bei Incident-Diagnose kann das Fenster über die beiden Variablen erhöht werden, ohne Workflow-Jobnamen oder Required Contexts zu ändern.

## 5. Entkoppelte Online-Konvergenz (Async)
- Zusätzlich läuft im Release-Workflow ein synchrones Blocker-Gate `enforce-online-convergence`, das nach Publish die Endpunkt-Konvergenz strikt erzwingt (auch für `workflow_dispatch`-Releases).
- Workflow: `.github/workflows/nuget-online-convergence.yml`
- Trigger: `workflow_run` nach erfolgreichem `Release Publish`.
- Trigger: `workflow_run` nach erfolgreichem `Release Publish` (unabhängig davon, ob via Tag-Push oder `workflow_dispatch` ausgelöst).
- Der Async-Workflow prüft weiterhin **alle** Endpunkte als harte Konvergenzbedingungen:
- `REQUIRE_SEARCH=1`
- `REQUIRE_REGISTRATION=1`
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -35,7 +35,7 @@ Map repo/governance-based Scorecard alerts without a concrete file (`no file ass
| `BranchProtectionID` | `main` only via PR + required checks | branch protection/ruleset active, required checks configured | `gh api repos/tomtastisch/FileClassifier/branches/main/protection` | `required_status_checks` present | direct push to `main` is technically blocked |
| `CodeReviewID` | at least 1 PR review before merge | PR review policy in branch protection/ruleset | `gh api repos/tomtastisch/FileClassifier/branches/main/protection --jq '.required_pull_request_reviews'` | `required_approving_review_count >= 1` | merge without review not possible |
| `MaintainedID` | evidence of active maintenance | continuous commits/releases + active CI | `gh api repos/tomtastisch/FileClassifier/commits?per_page=20` and `gh api repos/tomtastisch/FileClassifier/actions/runs?per_page=20` | commits exist in last 90 days | successful workflow runs exist in last 30 days |
| `FuzzingID` | fuzzing baseline exists (at least report-only) | workflow `.github/workflows/fuzzing-baseline.yml` | `gh workflow view fuzzing-baseline.yml --yaml` and `gh run list --workflow fuzzing-baseline.yml --limit 10` | workflow exists and is executable | at least one successful run in last 30 days |
| `FuzzingID` | fuzzing baseline exists (additionally enforced as a release blocker) | workflow `.github/workflows/fuzzing-baseline.yml` | `gh workflow view fuzzing-baseline.yml --yaml` and `gh run list --workflow fuzzing-baseline.yml --limit 10` | workflow exists and is executable | at least one successful run in last 30 days |
| `CIIBestPracticesID` | process/security baseline documented and traceable | audit/governance docs + CI evidence + security policy | `ls docs/audit` + `bash tools/audit/verify-security-claims.sh` | audit index exists and links | security claims evidence returns `pass` for blocker claims |

## Note on Scorecard Interpretation
Expand Down
3 changes: 2 additions & 1 deletion docs/1_en/ci/002_NUGET_TRUSTED_PUBLISHING.MD
Original file line number Diff line number Diff line change
Expand Up @@ -33,8 +33,9 @@ The active trusted-publishing policy is bound to the following identity:
- For incident diagnostics, the window can be increased via these variables without changing workflow job names or required contexts.

## 5. Decoupled Online Convergence (Async)
- The release workflow now also contains a synchronous blocker gate `enforce-online-convergence` that strictly enforces endpoint convergence after publish (including `workflow_dispatch` releases).
- Workflow: `.github/workflows/nuget-online-convergence.yml`
- Trigger: `workflow_run` after a successful `Release Publish`.
- Trigger: `workflow_run` after a successful `Release Publish` (independent of whether the release was triggered by tag push or `workflow_dispatch`).
- The async workflow still checks **all** endpoints as hard convergence conditions:
- `REQUIRE_SEARCH=1`
- `REQUIRE_REGISTRATION=1`
Expand Down
2 changes: 1 addition & 1 deletion docs/audit/013_SCORECARD_GOVERNANCE_ALERT_MAPPING.MD
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@ Diese Datei mappt die repo-/governance-basierten Scorecard-Alerts ohne konkrete
| `BranchProtectionID` | `main` nur via PR + required checks | Branch Protection/Ruleset aktiv, required checks konfiguriert | `gh api repos/tomtastisch/FileClassifier/branches/main/protection` | `required_status_checks` vorhanden | direkter Push auf `main` technisch blockiert |
| `CodeReviewID` | Mindestens 1 PR-Review vor Merge | PR-Review-Policy in Branch Protection/Ruleset | `gh api repos/tomtastisch/FileClassifier/branches/main/protection --jq '.required_pull_request_reviews'` | `required_approving_review_count >= 1` | Merge ohne Review nicht möglich |
| `MaintainedID` | Nachweis aktiver Wartung | Kontinuierliche Commits/Releases + aktive CI | `gh api repos/tomtastisch/FileClassifier/commits?per_page=20` und `gh api repos/tomtastisch/FileClassifier/actions/runs?per_page=20` | in den letzten 90 Tagen Commits vorhanden | in den letzten 30 Tagen erfolgreiche Workflow-Runs vorhanden |
| `FuzzingID` | Fuzzing-Baseline vorhanden (mind. report-only) | Workflow `.github/workflows/fuzzing-baseline.yml` | `gh workflow view fuzzing-baseline.yml --yaml` und `gh run list --workflow fuzzing-baseline.yml --limit 10` | Workflow existiert und ist ausführbar | mindestens ein erfolgreicher Run in den letzten 30 Tagen |
| `FuzzingID` | Fuzzing-Baseline vorhanden (zusätzlich als Release-Blocker aktiviert) | Workflow `.github/workflows/fuzzing-baseline.yml` | `gh workflow view fuzzing-baseline.yml --yaml` und `gh run list --workflow fuzzing-baseline.yml --limit 10` | Workflow existiert und ist ausführbar | mindestens ein erfolgreicher Run in den letzten 30 Tagen |
| `CIIBestPracticesID` | Prozess-/Security-Baseline dokumentiert und nachvollziehbar | Audit-/Governance-Docs + CI-Evidence + Security Policy | `ls docs/audit` + `bash tools/audit/verify-security-claims.sh` | Audit-Index vorhanden und verlinkt | Security-Claims-Evidence liefert `pass` für Blocker-Claims |

## Hinweis zur Scorecard-Interpretation
Expand Down
2 changes: 1 addition & 1 deletion docs/audit/113_SCORECARD_GOVERNANCE_ALERT_MAPPING.MD
Original file line number Diff line number Diff line change
Expand Up @@ -35,7 +35,7 @@ Map repo/governance-based Scorecard alerts without a concrete file (`no file ass
| `BranchProtectionID` | `main` only via PR + required checks | branch protection/ruleset active, required checks configured | `gh api repos/tomtastisch/FileClassifier/branches/main/protection` | `required_status_checks` present | direct push to `main` is technically blocked |
| `CodeReviewID` | at least 1 PR review before merge | PR review policy in branch protection/ruleset | `gh api repos/tomtastisch/FileClassifier/branches/main/protection --jq '.required_pull_request_reviews'` | `required_approving_review_count >= 1` | merge without review not possible |
| `MaintainedID` | evidence of active maintenance | continuous commits/releases + active CI | `gh api repos/tomtastisch/FileClassifier/commits?per_page=20` and `gh api repos/tomtastisch/FileClassifier/actions/runs?per_page=20` | commits exist in last 90 days | successful workflow runs exist in last 30 days |
| `FuzzingID` | fuzzing baseline exists (at least report-only) | workflow `.github/workflows/fuzzing-baseline.yml` | `gh workflow view fuzzing-baseline.yml --yaml` and `gh run list --workflow fuzzing-baseline.yml --limit 10` | workflow exists and is executable | at least one successful run in last 30 days |
| `FuzzingID` | fuzzing baseline exists (additionally enforced as a release blocker) | workflow `.github/workflows/fuzzing-baseline.yml` | `gh workflow view fuzzing-baseline.yml --yaml` and `gh run list --workflow fuzzing-baseline.yml --limit 10` | workflow exists and is executable | at least one successful run in last 30 days |
| `CIIBestPracticesID` | process/security baseline documented and traceable | audit/governance docs + CI evidence + security policy | `ls docs/audit` + `bash tools/audit/verify-security-claims.sh` | audit index exists and links | security claims evidence returns `pass` for blocker claims |

## Note on Scorecard Interpretation
Expand Down
3 changes: 2 additions & 1 deletion docs/ci/002_NUGET_TRUSTED_PUBLISHING.MD
Original file line number Diff line number Diff line change
Expand Up @@ -33,8 +33,9 @@ Die aktive Trusted-Publishing-Policy ist an folgende Identität gebunden:
- Bei Incident-Diagnose kann das Fenster über die beiden Variablen erhöht werden, ohne Workflow-Jobnamen oder Required Contexts zu ändern.

## 5. Entkoppelte Online-Konvergenz (Async)
- Zusätzlich läuft im Release-Workflow ein synchrones Blocker-Gate `enforce-online-convergence`, das nach Publish die Endpunkt-Konvergenz strikt erzwingt (auch für `workflow_dispatch`-Releases).
- Workflow: `.github/workflows/nuget-online-convergence.yml`
- Trigger: `workflow_run` nach erfolgreichem `Release Publish`.
- Trigger: `workflow_run` nach erfolgreichem `Release Publish` (unabhängig davon, ob via Tag-Push oder `workflow_dispatch` ausgelöst).
- Der Async-Workflow prüft weiterhin **alle** Endpunkte als harte Konvergenzbedingungen:
- `REQUIRE_SEARCH=1`
- `REQUIRE_REGISTRATION=1`
Expand Down
3 changes: 2 additions & 1 deletion docs/ci/102_NUGET_TRUSTED_PUBLISHING.MD
Original file line number Diff line number Diff line change
Expand Up @@ -33,8 +33,9 @@ The active trusted-publishing policy is bound to the following identity:
- For incident diagnostics, the window can be increased via these variables without changing workflow job names or required contexts.

## 5. Decoupled Online Convergence (Async)
- The release workflow now also contains a synchronous blocker gate `enforce-online-convergence` that strictly enforces endpoint convergence after publish (including `workflow_dispatch` releases).
- Workflow: `.github/workflows/nuget-online-convergence.yml`
- Trigger: `workflow_run` after a successful `Release Publish`.
- Trigger: `workflow_run` after a successful `Release Publish` (independent of whether the release was triggered by tag push or `workflow_dispatch`).
- The async workflow still checks **all** endpoints as hard convergence conditions:
- `REQUIRE_SEARCH=1`
- `REQUIRE_REGISTRATION=1`
Expand Down
3 changes: 2 additions & 1 deletion docs/versioning/002_HISTORY_VERSIONS.MD
Original file line number Diff line number Diff line change
Expand Up @@ -12,14 +12,15 @@ Heuristik für die Rückwirkungs-Zuordnung:
- `docs|test|ci|chore|tooling|refactor|fix` => Patch

Aktueller Entwicklungsstand:
- Aktuelle Entwicklungslinie enthält `6.x` (aktueller Arbeitsstand: `v6.1.13`; Details in `docs/versioning/003_CHANGELOG_RELEASES.MD`).
- Aktuelle Entwicklungslinie enthält `6.x` (aktueller Arbeitsstand: `v6.1.14`; Details in `docs/versioning/003_CHANGELOG_RELEASES.MD`).

Hinweis:
- Die Spalte `Keyword` verwendet den technischen Klassifizierungswert aus der Historie.
- Einzelne Committitel bleiben in der Originalsprache, wenn sie als exakter Quelltextnachweis übernommen wurden.

| Version | Kurzbeschreibung | Commit | Keyword |
|---|---|---|---|
| `6.1.14` | 6.1.14 Pipeline-Konvergenz geschlossen: Release-Workflow erzwingt NuGet-Online-Konvergenz jetzt fail-closed auch für `workflow_dispatch`, Release-Metadaten werden artefaktbasiert deterministisch aufgelöst und Fuzzing-Blocker-/Governance-Evidence-Dokumentation entsprechend nachgezogen | [unreleased](https://github.com/tomtastisch/FileClassifier/compare/main...HEAD) | patch |
Comment thread
tomtastisch marked this conversation as resolved.
| `6.1.13` | FC-0016 abgeschlossen: In-Code-XML-Dokumentation im gesamten CSCore sprachlich auf Deutsch vereinheitlicht (inkl. konsistenter `<b>`- und `<br/>`-Verwendungsstruktur) und Terminologie für Audit-/Betriebskontexte konsolidiert | [unreleased](https://github.com/tomtastisch/FileClassifier/compare/main...HEAD) | patch |
| `6.1.12` | FC-0015 abgeschlossen: Bilinguale Doku-Rasterstruktur in `docs/0_de` und `docs/1_en` mit identischer Dateimenge und verpflichtenden Language-Switch-Headern kanonisch eingeführt; Sync-Tooling fail-closed gehärtet (Parity/Switch-Checks + Stale-Pruning) und PR-Scope-Allowlist für die neue Struktur erweitert | [unreleased](https://github.com/tomtastisch/FileClassifier/compare/main...HEAD) | patch |
| `6.1.11` | FC-0014 abgeschlossen: Archive-/Path-Policy-Kernlogik (relative Archivpfad-Normalisierung und Root-Path-Policy) in CSCore zentralisiert (`ArchivePathPolicyUtility`) und via Bridge produktiv in `ArchiveEntryPathPolicy`/`DestinationPathGuard` genutzt; Telemetrie-/Contract-Abdeckung erweitert | [unreleased](https://github.com/tomtastisch/FileClassifier/compare/main...HEAD) | patch |
Expand Down
Loading
Loading