Repository navigation
Fix CI/CD errors, false positives, false negatives and warnings - #151
Conversation
Adding .gitkeep for PR creation (default mode). This file will be removed when the task is complete. Issue: #150
Store the run logs, annotations, run lists, issue/PR snapshots, the Ubuntu 24.04 nuget apt probe and actionlint/zizmor baselines under dev/log/issues/150/pulls/151 so the analysis is reproducible.
The shared cpp-test workflow ran `cmake --build .` and never executed bin/Platform.Interfaces.Tests, so failing tests stayed green. Add cpp/build-and-test.sh (Conan 2 + CMake + ctest --no-tests=error), register the GoogleTest cases with CTest, require GTest when tests are enabled, upgrade gtest to 1.18.0 to remove the Conan/CMake deprecation warnings of gtest/cci.20210126, and make the Gitpod scripts reuse the same entry point. experiments/cpp-false-positive-test-run.sh reproduces the old false positive with a deliberately failing test.
The *.log rule hid the downloaded run logs; allow everything under dev/log and ignore the CMakeUserPresets.json that conan install writes.
…ed keys pack-cpp-nuget.mjs replaces the apt nuget CLI that Ubuntu 24.04 no longer ships, preflight-nuget-release.mjs checks nuget.org for the version instead of only checking that a secret exists, and push-nuget-package.sh turns the bare 403 into guidance for renewing NUGET_TOKEN or fixing trusted publishing.
Test cpp now runs on every pull request that changes cpp/, runs the tests through CTest and packs the NuGet package with dotnet. Deploy new cpp version reuses it, checks nuget.org for the version, supports trusted publishing and creates the GitHub release only after the push succeeded.
The release preflight now checks nuget.org instead of only the presence of NUGET_TOKEN, the GitHub Packages push passes its API key, changed files come from git diff, and the status gate no longer runs on cancelled workflows.
AutoMerge relied on @dependabot comment commands that GitHub removed, so it passed without merging. It now enables auto-merge with gh and reports when the repository setting is off. Other workflows drop Node 20 actions and ubuntu-latest, declare permissions, and Dependabot also updates actions.
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
Cancel superseded pull request runs in every workflow while letting runs on main finish, so a release or documentation push is never interrupted (CI-CD-BEST-PRACTICES #10, same pattern as the C# template). Add a pinned secretlint scan like the JS template (#11) and an experiment that proves it can fail. Policy tests enforce both.
ci-logs-after holds the runs for c77f922: all green, no annotations, and the C++ job now executes 8 tests through CTest. upstream holds the bodies and lint evidence of linksplatform/Workflows#6, #7, #8 and link-foundation/csharp-ai-driven-development-pipeline-template#66.
Timeline, every problem with its class, evidence and fix, the status of each requirement, the template and best-practice comparison, and the actions left to maintainers (NuGet credentials, Allow auto-merge, releases without packages).
CodeQL's actions/unpinned-tag alert flagged zizmorcore/zizmor-action@v0.6.4 on this pull request. Only GitHub-owned actions keep tag pins now: the zizmor policy and the repository policy test no longer exempt zizmorcore.
Codacy reported 18 new markdownlint issues on this PR. Bare URLs, fences without a language and missing top-level headings are fixed. MD043 is enabled in Codacy without a heading list and flags every file with a heading (README.md included), so the archived evidence under dev/log is excluded from Codacy and disabling MD043 is listed as a maintainer action.
Working session summaryI fixed the last CI warnings on PR #151, and it is now ready for review: #151. Every check on the final commit What changed in this round:
Rest of the working session summary (1 KB)This summary was automatically extracted from the AI working session output. |
🤖 Solution Draft LogThis log file contains the complete execution trace of the AI solution draft process. 💰 Cost: $11.459406📊 Context and tokens usage:Claude Opus 5.5: (5 sub-sessions)
Total: (13.0K new + 500.7K cache writes + 16.9M cache reads) input tokens, 197.3K output tokens, $11.373312 cost Claude Haiku 4.5:
Total: 48.7K input tokens, 1.5K output tokens, $0.086094 cost 🤖 Models used:
📎 Log file uploaded as Gist (7778KB)Now working session is ended, feel free to review and add any feedback on the solution draft. |
|
Also check for cpp version - https://github.com/link-foundation/cpp-ai-driven-development-pipeline-template Do the same for it as in #150 Also bug must be reported to Hive Mind repository (https://github.com/link-assistant/hive-mind), as we didn't have https://github.com/link-foundation/cpp-ai-driven-development-pipeline-template listed in the issue and in docs. |
🔄 Auto-restart 1/5Reason: New comment(s) from non-bot user(s): konard Starting new session to address the issues. Auto-restart-until-mergeable mode is active. This run will stop after 5 restart iterations in total. |
nuget.org does validate API keys without publishing: the create-verification-key and verifykey endpoints that nuget push uses for symbol packages reject an invalid, expired or wrongly scoped key with 401/403. The release preflight now calls them when a version has to be published with NUGET_TOKEN, so the expired key from issue #150 fails the preflight instead of the push.
pipx 1.17 on the macOS image runs pip uninstall setuptools whenever it creates its shared venv; on Python 3.12+ that venv has no setuptools, so every macOS run logged 'WARNING: Skipping setuptools as it is not installed.' Only that exact stderr line is filtered; the exit status and every other line are kept.
Whitespace-only changes (git diff -w shows only line breaks and namespace closing comments) produced by the repository's .clang-format, so the new format check starts green.
… template The cpp-ai-driven-development-pipeline-template runs clang-format --dry-run --Werror with a version pinned through PyPI. Interfaces had a .clang-format but nothing enforced it: 56 violations in 7 headers before the previous commit (log in dev/log/issues/150/pulls/151/cpp-clang-format-before.log).
Without a published version the verifykey step cannot run, so only the key itself was checked; the preflight still printed that nuget.org accepted the key for this package. It now warns and names why the scope is unknown.
Only the csharp and CodeQL policy tests checked it; a new workflow could reintroduce the "Using 'master'" hint unnoticed.
…ue bodies cpp-template/comparison.md compares every file of cpp-ai-driven-development-pipeline-template@16bac38 with this repository, with what was adopted and why the rest was not. upstream/ holds the bodies and evidence for the C++, csharp and python template issues and the pipx issue.
…am issues in the analysis
…check" This reverts commit 83d7023.
…zizmor pass offline conan profile detect always ends with untagged advice that the profile is a guess; core:skip_warnings cannot select it. Exactly those lines are filtered, and a test runs build-and-test.sh with a stub conan to prove other warnings still reach the log. The pedantic zizmor pass now says --offline instead of warning that it fell back to offline mode.
…ile path Codacy's ESLint security rule flagged readFileSync with a non-literal path.
Working session summaryPR #151 is ready for review: #151. All 25 checks pass on the final commit CI log warnings removed in this round
On Rest of the working session summary (2 KB)This summary was automatically extracted from the AI working session output. |
🔄 Auto-restart-until-mergeable Log 1/5This log file contains the complete execution trace of the AI solution draft process. 💰 Cost: $12.818108📊 Context and tokens usage:Claude Opus 5.5: (5 sub-sessions)
Total: (15.8K new + 503.8K cache writes + 23.7M cache reads) input tokens, 198.1K output tokens, $12.795999 cost Claude Haiku 4.5:
Total: 10.2K input tokens, 375 output tokens, $0.022109 cost 🤖 Models used:
📎 Log file uploaded as Gist (17854KB)Now working session is ended, feel free to review and add any feedback on the solution draft. |
🎉 Auto-mergedThis pull request has been automatically merged by hive-mind.
Auto-merged by hive-mind with --auto-merge flag |
Summary
This PR fixes every error, warning, false positive and false negative in the CI/CD runs listed in #150. It also adds guards so they cannot come back. The full case study is in
dev/log/issues/150/pulls/151/analysis.md. It covers the timeline, the evidence with log line numbers, the comparison with the C#, JS, Python and C++ templates, and best-practice compliance. All raw logs are kept next to it.Errors
pushToNugetreturned 403. TheNUGET_TOKENsecret dates from 2022-12-02 and has expired. The newpreflight-nuget-release.mjsreports whether the version is already on nuget.org and which credential is available. Trusted publishing (NuGet/login, OIDC) is used when theNUGET_USERvariable is set, and the secret is the fallback.push-nuget-package.shskips versions that are already published and turns a 403 into instructions.apt-get install nugetno longer exists on Ubuntu 24.04. The C++ package is now packed withdotnet packand verified in the test workflow, then pushed withdotnet nuget push. Everything runs from local workflows instead oflinksplatform/Workflows@main.False positives
cpp_0.3.43,cpp_0.4.0andcpp_0.4.1were created even though the NuGet push failed.publishReleasenowneeds: [test, pushToNuget].cpp/build-and-test.shnow runs CTest with--no-tests=error, and gtest is upgraded to 1.18.0.False negatives
types: [edited].@dependabot mergecommands were removed, the bot check usedgithub.actor, and the repository has "Allow auto-merge" off. It now usesfetch-metadataandgh pr merge --auto. While the setting is off, the job fails with an error that names it.Workflowsworkflow runs actionlint (Docker image, includes shellcheck) and zizmor, and now reports 0 findings. CodeQL also coversactions, and dependency review runs on PRs.tj-actions/changed-files(CVE-2025-30066) is replaced bygit diff.README.mdincluded..codacy.ymltherefore excludes the archived evidence underdev/log/. Codacy now reports "up to standards".Warnings and notices
upload-artifact@v4andncipollo/release-action.ubuntu-latestmigration notices are gone; jobs run onubuntu-24.04.nuget.configonly moved the empty set and was reverted. The analyze step setsCODEQL_EXTRACTOR_CSHARP_BUILDLESS_NUGET_FEEDS_CHECK=falseinstead.Requires-PythonDeprecationWarning (pipx 1.16, already fixed in 1.17).profile detectadvice ("This profile is a guess…", and "Defaulted to cppstd='gnu17'" on macOS) is filtered line by line incpp/build-and-test.sh. A test with a stubconanshows that other warnings still get through.--offlineexplicitly, so it no longer warns that it fell back to offline mode. The action step before it runs the online audits.Best practices from the templates and CI-CD-BEST-PRACTICES.md
permissions.timeout-minuteson every job.persist-credentials: false.zizmorcore/zizmor-action, which CodeQL'sactions/unpinned-tagflagged on this PR. Onlyactions/*andgithub/*keep tag pins.!cancelled()instead ofalways().main.Secretsworkflow.cooldown..github/scripts/workflow-policy.test.mjs) enforce each rule in every workflow.C++ template (konard's comment)
cpp-template/comparison.mdcompares every file of link-foundation/cpp-ai-driven-development-pipeline-template at16bac38and gives the reason for each practice that was not adopted. Adopted:Test cppruns the 8 tests with GCC 13, Clang 18, AppleClang 17 and MSVC 19.51, plus GCC with ASan+UBSan.experiments/cpp-sanitizers-catch-errors.shshows that the sanitized build catches errors the plain build misses.clang-format==23.1.3with--dry-run --Werror. 56 existing violations were fixed.LINKS_PLATFORM_TESTS), and the hard-coded-marchflags were removed. They never matchedarmv7loraarch64.Upstream reports
Each report includes a reproduction, a workaround and a suggested fix.
apt-get install nugetfails on 24.04, and the release is created without the package.cpp-test.ymlnever runs the tests.ubuntu-latest,@mainreferences, and 114 zizmor findings.-latestrunners, tag-pinned actions with open CodeQL alerts, and Git's default-branch hint.fix --ci-cdandCI-CD-BEST-PRACTICES.mddo not know the C++ template, so Check for all false positives, false negatives, warnings and errors in CI/CD and fix them all #150 did not list it although C++ is 76% of this repository.Required maintainer actions
These cannot be done from a PR.
NUGET_USER, or renew theNUGET_TOKENsecret. The unpublished C# 0.6.1 and C++ 0.4.1 will then be published by the next run onmain. No version bump is needed.DEPENDABOT_AUTO_MERGE_TOKEN(last updated in 2021) is still valid.cpp_0.3.43,cpp_0.4.0andcsharp_0.5.1. Their NuGet packages do not exist. I left them untouched.Reproduction
dev/log/issues/150/pulls/151/nuget-apt-probe.logshowsdocker run ubuntu:24.04 apt-get install nugetfailing with "Unable to locate package nuget", the same exit 100 as run 36213155523.experiments/cpp-false-positive-test-run.shadds an always-failing gtest. The old build steps exit 0; the new script fails (cpp-false-positive-experiment.log).ci-logs/run-36213154898.log.Verification
node --test .github/scripts/*.test.mjs: 102 passed. The new policy assertions were mutation-tested. The new tests for the Conan filter and the CodeQL setting fail without the fix.check-readme-badges.mjspass.dev/log/.../lint/*-after.txt).experiments/secretlint-detects-planted-secret.shproves the secret scan can fail.experiments/cpp-false-positive-test-run.sh: a failing gtest now failscpp/build-and-test.sh.d269d46(ci-logs-after/d269d46/):warnanddeprecatfinds only config dumps, test names and the filter lines themselves.Fixes #150.
Changes
.codacy.yml.github/dependabot.yml.github/scripts/check-cpp-format.sh.github/scripts/check-cpp-nuget-package.sh.github/scripts/check-cpp-nuget-package.test.mjs.github/scripts/codeql-workflow-policy.test.mjs.github/scripts/cpp-build-and-test.test.mjs.github/scripts/cpp-workflow-policy.test.mjs.github/scripts/csharp-workflow-policy.test.mjs.github/scripts/pack-cpp-nuget.mjs.github/scripts/pack-cpp-nuget.test.mjs.github/scripts/preflight-csharp-release.mjs.github/scripts/preflight-csharp-release.test.mjs.github/scripts/preflight-nuget-release.mjs.github/scripts/preflight-nuget-release.test.mjs.github/scripts/push-nuget-package.sh.github/scripts/push-nuget-package.test.mjs.github/scripts/workflow-jobs.mjs.github/scripts/workflow-policy.test.mjs.github/workflows/AutoMerge.yml.github/workflows/codeql.yml.github/workflows/cpp-docs.yml.github/workflows/cpp-test.yml.github/workflows/csharp.yml.github/workflows/deploy-cpp.yml.github/workflows/readme-badges.yml.github/workflows/secrets.yml.github/workflows/workflows.yml.github/zizmor.yml.gitignore.gitpod.yml.secretlintrc.jsoncpp/CMakeLists.txtcpp/Platform.Interfaces/CArray.hcpp/Platform.Interfaces/CDictionary.hcpp/Platform.Interfaces/CLinkAddress.hcpp/Platform.Interfaces/CList.hcpp/Platform.Interfaces/CProperty.hcpp/Platform.Interfaces/CSet.hcpp/Platform.Interfaces/Macros.hcpp/build-and-test.shcpp/conanfile.txtcpp/nuget/TemplateLibrary.targetscpp/nuget/icon.pngcpp/run-tests-gitpod.shcpp/setup-gitpod.shdev/log/issues/150/pulls/151/analysis.mddev/log/issues/150/pulls/151/ci-logs-after/1c4ba2d/annotations.txtdev/log/issues/150/pulls/151/ci-logs-after/1c4ba2d/run-37528763507.logdev/log/issues/150/pulls/151/ci-logs-after/1c4ba2d/run-37528763519.log