Resolves the review of this branch (one Major, three Minor findings):
- Major: a Dependabot pull request runs the action versions it proposes
before anyone reviews them, and the wiki job of that run held
contents: write. The wiki job is now read-only and only previews the
changed pages; the new publish-wiki job, the only one besides release
with write access, publishes for master alone, after a merge.
dependabot.yml waits 7 days (cooldown) before it proposes a release.
- Minor: Repository.Tests.ps1 asserts that it found the 3 packages.config
files, checks version 2 and the directory, accepts either quote style,
and checks that the "*" pattern sits under groups (11 tests; the
cooldown test failed before the change).
Memory Bank: Decision 11 and techContext.md describe the two wiki jobs.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- .github/dependabot.yml: weekly updates for the github-actions ecosystem
only, grouped into one pull request with the commit prefix "ci". The CI
workflow pins each action by commit SHA with a version comment, which
Dependabot updates together.
- NTFSSecurity/packages.config listed AlphaFS 2.2.6, but every HintPath and
the other packages.config files use 2.2.1, the version that ships.
- Tests/Repository.Tests.ps1 (new, 8 tests, no build needed) checks both;
before the change, 5 of them failed.
No CHANGELOG entry: build and CI metadata only (Decision 7).
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Pushing a tag such as 5.0.0 or 5.0.0-rc1 on master now publishes the
package that the build job built and tested to the PowerShell Gallery
and creates the GitHub release with NTFSSecurity.zip.
- New-ModulePackage.ps1 copies only the FileList files of the Release
build, so no debug symbols, XML documentation, or copy of
System.Management.Automation.dll ship. It builds the nupkg with
Compress-PSResource and adds the command tags (PSIncludes_Cmdlet,
PSCmdlet_*, PSCommand_*) that PSResourceGet leaves out and that the
Gallery uses to list cmdlets and that Find-Command searches. Every CI
run builds and uploads the packages.
- Get-ReleaseInfo.ps1 returns the version and release notes: a dated
CHANGELOG section for a release, the [Unreleased] section for a
prerelease.
- The release job checks that the tag matches the manifest version and
points to a commit on master, reads the API key from the environment
powershell-gallery, and skips steps already done, so a rerun is safe.
- The manifest gets the prerelease label rc1 and a release notes link;
the 5.0.0 changelog entries move back to [Unreleased] until the final
release.
- Tests/Release.Tests.ps1 covers both scripts and the packages; the
changelog check moves there from Manifest.Tests.ps1.
- Docs/Contributing/05-Releasing.md describes the one-time setup and the
release steps; Docs/README.md explains -AllowPrerelease.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
.github/workflows/ci.yml replaces appveyor.yml and runs on pull requests
and pushes to master:
- build (windows-2025): the same restore, Release build, and documentation
checks as before, then the Pester tests in Windows PowerShell 5.1 and in
PowerShell 7. .github/scripts/Invoke-Tests.ps1 writes the counts and
the failed tests to the job summary and the NUnit file to the
test-results artifact, and also fails on test files that fail.
- wiki (ubuntu-latest): generates the wiki from Docs; on pull requests it
lists the pages that would change, from master it publishes them with
the built-in token. Only this job has contents: write.
Actions are pinned by commit SHA. Every native command checks its exit
code, because GitHub checks only the last one. The contributor guide
describes the workflow and the wiki.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- .github/scripts/Export-WikiContent.ps1 converts Docs, except the
contributor guide, into flat wiki pages: Docs/README.md becomes Home,
cmdlet pages lose their platyPS metadata, links point to wiki pages or
to the files on GitHub, and links in code stay unchanged. It writes a
sidebar from the cmdlet groups of Docs/README.md, a footer, and the
former page How-to-install, and keeps the page name Version-History
that the release notes link to.
- Tests/Wiki.Tests.ps1 checks the conversion rules with a sample of Docs
and every link and anchor of the wiki generated from the real Docs.
- README, CHANGELOG, and the version history mention the wiki again.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>