Skip to content

Add LanguageTags audit report - #234

Merged
ptr727 merged 1 commit into
developfrom
feature/audit-languagetags
Jul 5, 2026
Merged

Add LanguageTags audit report#234
ptr727 merged 1 commit into
developfrom
feature/audit-languagetags

Conversation

@ptr727

@ptr727 ptr727 commented Jul 5, 2026

Copy link
Copy Markdown
Owner

Third per-repo audit (AUDIT.md): ptr727/LanguageTags main @ 7322d72, types csharp+nuget+codegen. Verdict: operational - no defects, 11 drift findings.

Clean: codegen output input-deterministic (static [GeneratedCode] stamp, main/develop matrix each opening its own PR); nuget genuine OIDC (NuGet/login ephemeral key, no stored NUGET_API_KEY, --skip-duplicate); [*.cs] block, analyzer enforcement, SHA-pinning, secrets, cspell en-US. The ...status job ruleset naming matches the aggregator (new fleet canonical, not flagged).

Recurring drifts (now 3 repos): continuous push-publish vs two-phase, github.ref_name without IGNORE_GITHUB_REF, plain release-asset seam, no paths-filter, missing global [*] end_of_line default (now caught by #233), off-baseline repo-config/ruleset-*.json filenames.

New spec gap surfaced: NUGET_USERNAME is required by the OIDC NuGet/login but spec/secrets.json models nuget-oidc as requires: [] - queued for the maintainer.

🤖 Generated with Claude Code

Third per-repo audit (csharp+nuget+codegen). Verdict: operational; no defects, 11 drift findings. codegen output is input-deterministic (static GeneratedCode stamp, matrix over main/develop each opening its own PR); nuget is genuine OIDC Trusted Publishing (NuGet/login ephemeral key, no stored NUGET_API_KEY, --skip-duplicate). Recurring cross-repo drifts confirmed (now 3 repos): continuous push-publish vs two-phase, github.ref_name without IGNORE_GITHUB_REF, plain release-asset seam, no paths-filter, missing global [*] end_of_line default, skip-not-fail dispatch guard, off-baseline repo-config filenames. New spec gap: NUGET_USERNAME is required by nuget-oidc (NuGet/login) but spec/secrets.json models nuget-oidc as requires:[].

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Signed-off-by: Pieter Viljoen <ptr727@users.noreply.github.com>
Copilot AI review requested due to automatic review settings July 5, 2026 03:55

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds the third per-repo audit report for ptr727/LanguageTags (main @ 7322d72), capturing the audit verdict (operational), drift findings, and proposed spec/registry follow-ups in the central reports/ area of this governance repo.

Changes:

  • Add a new audit report markdown file for the LanguageTags repository.
  • Document develop/main drift status, dimension-by-dimension results, and WORKFLOW.md 5A/5B trace outcomes.
  • Record a spec gap candidate (NUGET_USERNAME requirement for NuGet OIDC) and recurring drift signals for future machine checks.

@ptr727
ptr727 merged commit 9a63976 into develop Jul 5, 2026
7 checks passed
@ptr727
ptr727 deleted the feature/audit-languagetags branch July 5, 2026 03:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants