Centralize .NET Build and Package Configuration per the Fleet - #589
Conversation
Move the shared project properties into a root Directory.Build.props, adding AnalysisMode All and TreatWarningsAsErrors, and move every package version into a root Directory.Packages.props with central package management, leaving each PackageReference versionless. Mark CreateMatrix IsAotCompatible for every build. Reference verification stays scoped to an AOT publish, since System.CommandLine, the Serilog sinks, and the Polly assemblies are not built as AOT-compatible and verifying them fails every build with IL3058. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The AOT publish CODESTYLE.md documents failed once warnings became errors, since reference verification raises IL3058 for dependencies not built as AOT-compatible. Keep IL3058 a warning in that configuration and correct the dependency list the note gives. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Warning Review limit reachedNext included review available in 10 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (6)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## develop #589 +/- ##
========================================
Coverage 57.01% 57.01%
========================================
Files 15 15
Lines 1375 1375
Branches 108 108
========================================
Hits 784 784
Misses 573 573
Partials 18 18 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The changes consistently centralize build and package configuration without introducing inconsistencies across the two projects or contradicting the documented AOT publish approach.
Review effort: Lite
Findings: None
What changed in this PR
Centralizes the repository’s .NET build and NuGet package configuration into root-level Directory.Build.props and Directory.Packages.props, aligning both projects with the fleet’s “central props + central package management” model while preserving the repo’s opt-in AOT publish behavior.
Changes:
- Added root
Directory.Build.propsto standardize target framework, analyzers, nullable, and warnings-as-errors policy. - Added root
Directory.Packages.propsto enable Central Package Management and consolidate all NuGet versions. - Simplified both
.csprojfiles to inherit shared configuration and use versionlessPackageReference, with AOT compatibility handling scoped to AOT publish.
| File | Description |
|---|---|
| NxWitness.slnx | Adds the new central props files to solution items for discoverability. |
| Directory.Packages.props | Enables central package management and defines all package versions once. |
| Directory.Build.props | Centralizes shared .NET build/analyzer configuration and warnings-as-errors policy. |
| CreateMatrixTests/CreateMatrixTests.csproj | Removes duplicated build properties and switches to versionless package references. |
| CreateMatrix/CreateMatrix.csproj | Removes duplicated build properties, switches to versionless package references, and scopes IL3058 to remain a warning during AOT publish. |
| CODESTYLE.md | Documents the repo’s AOT publish scoping and rationale alongside other NxWitness .NET conventions. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Promotes `develop` at `54e66f5` to `main`: - #588, which resyncs the instruction set and the carried Skills tree with the hub. - #589, which centralizes the .NET build and package configuration per the fleet. - The Dependabot bumps merged on `develop` since the last promotion. It is opened from a branch off `main` rather than from `develop`, because both project files conflicted. `develop` moved their versions into `Directory.Packages.props`, while `main` took the same Dependabot bumps inline. Every version `main` carries equals the one `Directory.Packages.props` declares, and every property it keeps moved to `Directory.Build.props` with the same value. So the resolution takes `develop`'s side, and the merged tree is byte-identical to `develop` (`git diff 54e66f5 HEAD` is empty). The workflow action bumps `main` took directly are already on `develop`, so nothing `main`-only is dropped. Merge with `--merge`, per the promotion convention. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
Conforms the .NET projects to the fleet's
dotnet-codestylerules, a finding the resync in #588 left open.Directory.Build.propsat the root carries the shared properties:TargetFramework,LangVersion,Nullable, the full analyzer set (AnalysisLevel latest-all,AnalysisMode All),TreatWarningsAsErrors, andIsPackable. Of those,AnalysisMode AllandTreatWarningsAsErrorsare new to this repo, and the build is clean under both.Directory.Packages.propsenables central package management and declares every version once. Both.csprojfiles now carry versionlessPackageReferenceitems, and every name and version carries over unchanged. Dependabot's NuGet entry already reads from/.CreateMatrix.csprojisIsAotCompatiblefor every build.VerifyReferenceAotCompatibilitystays scoped to an AOT publish, the shape PhotoCleaner uses, becauseSystem.CommandLine, the Serilog enricher and sink, and the assembliesMicrosoft.Extensions.Http.Resiliencebrings in are not built as AOT-compatible. In that configurationIL3058stays a warning, so the documented-p:PublishAot=truepublish still produces the native binary. The skill's own text states the verification as unconditional, which fails with these dependencies, and that is filed at the source as Scope VerifyReferenceAotCompatibility to an AOT Publish in dotnet-codestyle ProjectTemplate#1857.NxWitness.slnxlists the two props files, andCODESTYLE.md"NxWitness .NET Conventions" records the AOT scoping.With
TreatWarningsAsErrorson, a NuGet audit advisory against any direct or transitive dependency now fails restore until a Dependabot bump lands. That matches every conformant fleet repo, none of which exemptsNU1901-NU1904.Local verification:
dotnet buildwith 0 warnings and 0 errors,dotnet format style --verify-no-changes --severity=infoand CSharpier clean, all 21 tests passing (test executable run directly), the AOT publish producing its binary, and markdownlint and the prose gate clean. Three adversarial local review rounds, the last with no findings.🤖 Generated with Claude Code