From b2ef4a31580dabc2b35881ef3d3bb6ed2643a959 Mon Sep 17 00:00:00 2001 From: Josh Hiles <11314656+JoshHiles@users.noreply.github.com> Date: Wed, 24 Sep 2025 10:24:43 +0100 Subject: [PATCH 1/4] ci: Add pull request actions and update release script --- .github/workflows/codeql.yaml | 40 +++++++++++++++++++++++++++++ .github/workflows/release.yaml | 12 ++++----- .github/workflows/unit-test.yaml | 44 ++++++++++++++++++++++++++++++++ NuGet.config | 2 +- 4 files changed, 91 insertions(+), 7 deletions(-) create mode 100644 .github/workflows/codeql.yaml create mode 100644 .github/workflows/unit-test.yaml diff --git a/.github/workflows/codeql.yaml b/.github/workflows/codeql.yaml new file mode 100644 index 0000000..f583af4 --- /dev/null +++ b/.github/workflows/codeql.yaml @@ -0,0 +1,40 @@ +name: "CodeQL" + +on: + push: + branches: [ "master" ] + pull_request: + branches: [ "master" ] + +jobs: + analyze: + name: Analyze + runs-on: ubuntu-latest + permissions: + security-events: write + packages: read + actions: read + contents: read + + strategy: + fail-fast: false + matrix: + include: + - language: actions + build-mode: none + - language: csharp + build-mode: none + + steps: + - uses: actions/checkout@v5 + + - name: Initialize CodeQL + uses: github/codeql-action/init@v3 + with: + languages: ${{ matrix.language }} + build-mode: ${{ matrix.build-mode }} + + - name: Perform CodeQL Analysis + uses: github/codeql-action/analyze@v3 + with: + category: "/language:${{matrix.language}}" diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index 1d6389b..3b4d118 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -1,4 +1,3 @@ -# This runs when a tag gets pushed matching the format below name: Release on: @@ -12,7 +11,7 @@ env: jobs: build: - runs-on: ubuntu-latest + runs-on: windows-latest steps: - uses: actions/checkout@v5 @@ -23,24 +22,25 @@ jobs: uses: actions/setup-dotnet@v5 with: dotnet-version: 8.0.x + cache-dependency-path: subdir/packages.lock.json - name: Restore - run: dotnet restore + run: dotnet restore --locked-mode - name: Build run: dotnet build --configuration Release --no-restore - name: Test - run: dotnet test --configuration Release --no-build --verbosity normal + run: dotnet test --configuration Release --no-build --no-restore --verbosity normal - name: Pack - run: dotnet pack --configuration Release -p:PackageVersion=${{ github.ref_name }} --output artifacts/ + run: dotnet pack --no-build --no-restore --configuration Release -p:PackageVersion=${{ github.ref_name }} --output artifacts/ - name: Publish to GitHub working-directory: artifacts run: | dotnet nuget add source --username ${{ github.actor }} --password ${{ secrets.GITHUB_TOKEN }} --store-password-in-clear-text --name github "https://nuget.pkg.github.com/scientistproject/index.json" - dotnet nuget push --source github *.nupkg + dotnet nuget push *.nupkg --api-key ${{ secrets.GITHUB_TOKEN }} --source github - name: Publish to NuGet working-directory: artifacts diff --git a/.github/workflows/unit-test.yaml b/.github/workflows/unit-test.yaml new file mode 100644 index 0000000..36820be --- /dev/null +++ b/.github/workflows/unit-test.yaml @@ -0,0 +1,44 @@ +name: Unit test + +on: + pull_request: + branches: ["master"] + +env: + DOTNET_CLI_TELEMETRY_OPTOUT: true + DOTNET_NOLOGO: true + DOTNET_SKIP_FIRST_TIME_EXPERIENCE: true + +jobs: + build: + strategy: + fail-fast: false + matrix: + include: + - framework: net8.0 + sdk: 8.0.x + os: ubuntu-latest + - framework: net48 + sdk: none + os: windows-latest + + runs-on: ${{ matrix.os }} + + steps: + - uses: actions/checkout@v5 + + - name: Setup .NET (skip for net48) + if: matrix.sdk != 'none' + uses: actions/setup-dotnet@v5 + with: + dotnet-version: ${{ matrix.sdk }} + cache-dependency-path: subdir/packages.lock.json + + - name: Restore + run: dotnet restore --locked-mode + + - name: Build + run: dotnet build --configuration Release --no-restore + + - name: Test + run: dotnet test --no-build --no-restore --framework ${{ matrix.framework }} --configuration Release --verbosity normal \ No newline at end of file diff --git a/NuGet.config b/NuGet.config index 2805dff..6ce9759 100644 --- a/NuGet.config +++ b/NuGet.config @@ -1,4 +1,4 @@ - + From c9f88b9affd1c4b149683c3de7ee595048f84b6c Mon Sep 17 00:00:00 2001 From: Josh Hiles <11314656+JoshHiles@users.noreply.github.com> Date: Wed, 24 Sep 2025 10:30:20 +0100 Subject: [PATCH 2/4] ci: add permissions for actions --- .github/workflows/release.yaml | 4 ++++ .github/workflows/unit-test.yaml | 5 ++++- 2 files changed, 8 insertions(+), 1 deletion(-) diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index 3b4d118..2506c4b 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -11,6 +11,10 @@ env: jobs: build: + permissions: + contents: read + packages: write + runs-on: windows-latest steps: diff --git a/.github/workflows/unit-test.yaml b/.github/workflows/unit-test.yaml index 36820be..0b29998 100644 --- a/.github/workflows/unit-test.yaml +++ b/.github/workflows/unit-test.yaml @@ -10,7 +10,10 @@ env: DOTNET_SKIP_FIRST_TIME_EXPERIENCE: true jobs: - build: + test: + permissions: + contents: read + strategy: fail-fast: false matrix: From 518e19d9da6332cfb78e01e5baeb6e166e7a882f Mon Sep 17 00:00:00 2001 From: Josh Hiles <11314656+JoshHiles@users.noreply.github.com> Date: Wed, 24 Sep 2025 10:36:49 +0100 Subject: [PATCH 3/4] ci: remove --locked-mode Locked mode fails on net48 --- .github/workflows/release.yaml | 2 +- .github/workflows/unit-test.yaml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index 2506c4b..231c370 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -29,7 +29,7 @@ jobs: cache-dependency-path: subdir/packages.lock.json - name: Restore - run: dotnet restore --locked-mode + run: dotnet restore - name: Build run: dotnet build --configuration Release --no-restore diff --git a/.github/workflows/unit-test.yaml b/.github/workflows/unit-test.yaml index 0b29998..3076a14 100644 --- a/.github/workflows/unit-test.yaml +++ b/.github/workflows/unit-test.yaml @@ -38,7 +38,7 @@ jobs: cache-dependency-path: subdir/packages.lock.json - name: Restore - run: dotnet restore --locked-mode + run: dotnet restore - name: Build run: dotnet build --configuration Release --no-restore From 4bce02ad8d3a3001d4f00130ba1a75b72c6496b1 Mon Sep 17 00:00:00 2001 From: Josh Hiles <11314656+JoshHiles@users.noreply.github.com> Date: Wed, 24 Sep 2025 18:16:24 +0100 Subject: [PATCH 4/4] ci: fix setup-dotnet wildcard subdir cache path --- .github/workflows/release.yaml | 2 +- .github/workflows/unit-test.yaml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index 231c370..14c5cf5 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -26,7 +26,7 @@ jobs: uses: actions/setup-dotnet@v5 with: dotnet-version: 8.0.x - cache-dependency-path: subdir/packages.lock.json + cache-dependency-path: '**/packages.lock.json' - name: Restore run: dotnet restore diff --git a/.github/workflows/unit-test.yaml b/.github/workflows/unit-test.yaml index 3076a14..ca7ea20 100644 --- a/.github/workflows/unit-test.yaml +++ b/.github/workflows/unit-test.yaml @@ -35,7 +35,7 @@ jobs: uses: actions/setup-dotnet@v5 with: dotnet-version: ${{ matrix.sdk }} - cache-dependency-path: subdir/packages.lock.json + cache-dependency-path: '**/packages.lock.json' - name: Restore run: dotnet restore