diff --git a/.github/workflows/dotnet.yml b/.github/workflows/dotnet.yml index b9b165e..298d5b3 100644 --- a/.github/workflows/dotnet.yml +++ b/.github/workflows/dotnet.yml @@ -1,10 +1,8 @@ name: .NET on: - push: - branches: [ ] pull_request: - branches: [ ] + branches: [ main ] jobs: build: @@ -12,11 +10,11 @@ jobs: runs-on: windows-latest steps: - - uses: actions/checkout@v2 - - name: Setup .NET - uses: actions/setup-dotnet@v1 + - uses: actions/checkout@v7 + - name: Setup .NET 10 + uses: actions/setup-dotnet@v5 with: - dotnet-version: 5.0.x + dotnet-version: 10.0.x - name: Add Exasol GH Nuget Source run: dotnet nuget add source --username exa-ci-1 --password ${{ secrets.GITHUB_TOKEN }} --store-password-in-clear-text --name github "https://nuget.pkg.github.com/EXASOL/index.json" - name: Restore dependencies diff --git a/.github/workflows/publish-on-tag.yml b/.github/workflows/publish-on-tag.yml index c6c2370..1f4a2d0 100644 --- a/.github/workflows/publish-on-tag.yml +++ b/.github/workflows/publish-on-tag.yml @@ -1,41 +1,51 @@ -name: publish to GH +name: Publish to GitHub Packages on: push: - branches: - - "!*" tags: - "*" +permissions: + contents: read + packages: write + jobs: - build: + publish: runs-on: windows-latest steps: - - uses: actions/checkout@v2 + - uses: actions/checkout@v7 - - name: Setup .NET 5 - uses: actions/setup-dotnet@v1 + - name: Setup .NET 10 + uses: actions/setup-dotnet@v5 with: - dotnet-version: 5.0.x + dotnet-version: 10.0.x - - name: NuGet Add Source + - name: Add Exasol GitHub NuGet source run: dotnet nuget add source --username exa-ci-1 --password ${{ secrets.GITHUB_TOKEN }} --store-password-in-clear-text --name github "https://nuget.pkg.github.com/EXASOL/index.json" - + - name: Restore dependencies run: dotnet restore - - name: Build - run: dotnet build --no-restore - - name: Test - run: dotnet test --no-build --verbosity normal - - name: pack - run: dotnet pack --configuration Release > packageoutput - - name: set variable - run: $cmdOutput = python .\print_package_path.py ; $cmdOutput; echo "NPPATH=$cmdOutput" | Out-File -FilePath $Env:GITHUB_ENV -Encoding utf-8 -Append; + - name: Build + run: dotnet build --configuration Release --no-restore - # https://stackoverflow.com/questions/57889719/how-to-push-nuget-package-in-github-actions - - name: NuGet Push to GH NuGet - run: dotnet nuget push ${{ env.NPPATH }} -s "github" --api-key ${{ secrets.GITHUB_TOKEN }} + - name: Test + run: dotnet test --configuration Release --no-build --verbosity normal + + - name: Pack + run: dotnet pack ./error-reporting-csharp-dotnet-tool/error-reporting-csharp-dotnet-tool.csproj --configuration Release --no-build --output ./artifacts/packages + + - name: Push to GitHub NuGet + shell: pwsh + run: | + $packages = Get-ChildItem -Path ./artifacts/packages -Filter *.nupkg + if (-not $packages) { + throw "No NuGet packages found in ./artifacts/packages." + } + + foreach ($package in $packages) { + dotnet nuget push $package.FullName --source "github" --api-key ${{ secrets.GITHUB_TOKEN }} --skip-duplicate + } diff --git a/README.md b/README.md index 7ca6bcd..edb3dcb 100644 --- a/README.md +++ b/README.md @@ -46,5 +46,6 @@ The short tag is the only parameter required, ## Additional Information +* [Changelog](doc/changes/changelog.md) * [License](LICENSE) diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..5c9e6f4 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,26 @@ +# Security + +If you believe you have found a new security vulnerability in this repository, please report it to us as follows. + +## Reporting Security Issues + +* Please do **not** report security vulnerabilities through public GitHub issues. + +* Please create a draft security advisory on the Github page: the reporting form is under `> Security > Advisories`. The URL is https://github.com/exasol/error-crawler-csharp/security/advisories/new. + +* If you prefer to email, please send your report to `infosec@exasol.com`. + +## Guidelines + +* When reporting a vulnerability, please include as much information as possible, including the complete steps to reproduce the issue. + +* Avoid sending us executables. + +* Feel free to include any script you wrote and used but avoid sending us scripts that download and run binaries. + +* We will prioritise reports that show how the exploits work in realistic environments. + +* We prefer all communications to be in English. + +* We do not offer financial rewards. We are happy to acknowledge your research publicly when possible. + diff --git a/doc/changes/changelog.md b/doc/changes/changelog.md new file mode 100644 index 0000000..e4dd4a8 --- /dev/null +++ b/doc/changes/changelog.md @@ -0,0 +1,3 @@ +# Changes + +* [1.0.0](changes_1.0.0.md) diff --git a/doc/changes/changes_1.0.0.md b/doc/changes/changes_1.0.0.md new file mode 100644 index 0000000..d78d047 --- /dev/null +++ b/doc/changes/changes_1.0.0.md @@ -0,0 +1,33 @@ +# error-crawler-csharp 1.0.0, released 2026-06-25 + +Code Name: Release Automation + +## Features / Enhancements + +* Updated the GitHub Packages publish workflow for tag-based releases. +* Removed the Python helper that parsed `dotnet pack` output. +* Updated the target .NET framework and refreshed dependencies. +* Added release documentation and a changelog. + +## Dependency Updates + +### `error-reporting-csharp-dotnet-tool/error-reporting-csharp-dotnet-tool.csproj` + +* Updated `TargetFramework` from `net5.0` to `net10.0` +* Updated `CommandLineParser` from `2.8.0` to `2.9.1` +* Added `Microsoft.Build.Framework` version `18.4.0` +* Updated `Microsoft.Build.Locator` from `1.4.1` to `1.11.2` +* Updated `Microsoft.CodeAnalysis` from `4.0.1` to `5.3.0` +* Updated `Microsoft.CodeAnalysis.CSharp` from `4.0.1` to `5.3.0` +* Updated `Microsoft.CodeAnalysis.Workspaces.MSBuild` from `4.0.1` to `5.3.0` +* Updated `MinVer` from `2.5.0` to `7.0.0` +* Updated `Newtonsoft.Json` from `13.0.1` to `13.0.4` +* Updated `NJsonSchema` from `10.6.5` to `11.6.1` + +### `error-reporting-csharp-dotnet-tool-tests/error-reporting-csharp-dotnet-tool-tests.csproj` + +* Updated `TargetFramework` from `net5.0` to `net10.0` +* Updated `Microsoft.NET.Test.Sdk` from `17.0.0` to `18.5.1` +* Updated `xunit.runner.visualstudio` from `2.4.3` to `3.1.5` +* Removed `xunit.runner.console` version `2.4.1` +* Replaced `xunit` version `2.4.1` with `xunit.v3` version `3.2.2` diff --git a/error-reporting-csharp-dotnet-tool-tests/Tests.cs b/error-reporting-csharp-dotnet-tool-tests/Tests.cs index 6f94bfe..421d62a 100644 --- a/error-reporting-csharp-dotnet-tool-tests/Tests.cs +++ b/error-reporting-csharp-dotnet-tool-tests/Tests.cs @@ -35,31 +35,22 @@ public void IntegrationTestNoProjectTag() } private static void PackageAndInstallTool() { - string output = RunCmd("cd ../../../.. && dotnet pack"); + RunCmd("cd ../../../.. && dotnet pack"); - string buildVersion = ExtractBuildVersionFromPackageOutput(output); - RunCmd($"cd ../../../.. && dotnet tool update -g --add-source .\\error-reporting-csharp-dotnet-tool\\nupkg\\ exasol-error-crawler --version {buildVersion}"); + string buildVersion = ExtractBuildVersionFromPackage(); + RunCmd($"cd ../../../.. && dotnet tool update -g --source .\\error-reporting-csharp-dotnet-tool\\nupkg\\ --source https://api.nuget.org/v3/index.json exasol-error-crawler --version {buildVersion}"); } - private static string ExtractBuildVersionFromPackageOutput(string output) + private static string ExtractBuildVersionFromPackage() { - string buildVersion = string.Empty; - string packagePathRegexStr = "(?<= Successfully created package ')[\\w\\:\\\\\\-\\.]*(?=')"; - Regex packagePathRegex = new Regex(packagePathRegexStr); - var packagePathMatch = packagePathRegex.Match(output); - if (packagePathMatch.Success) - { - string versionRegexStr = "(?<=crawler\\.)[\\w\\W]*(?=.nupkg)"; - Regex versionRegex = new Regex(versionRegexStr); - var versionMatch = versionRegex.Match(packagePathMatch.Value); - if (versionMatch.Success) - { - //https://stackoverflow.com/questions/19774155/returning-a-string-from-a-console-application - buildVersion = versionMatch.Value; - } - } + const string packageNamePrefix = "exasol-error-crawler."; + var packagePath = Directory.GetFiles(@"..\..\..\..\error-reporting-csharp-dotnet-tool\nupkg", $"{packageNamePrefix}*.nupkg") + .OrderByDescending(File.GetLastWriteTimeUtc) + .FirstOrDefault(); - return buildVersion; + Assert.False(string.IsNullOrEmpty(packagePath), "Could not find the packed exasol-error-crawler NuGet package."); + + return Path.GetFileNameWithoutExtension(packagePath).Substring(packageNamePrefix.Length); } private static void CheckResultingJSON() @@ -110,9 +101,9 @@ private static string RunCmd(string argument) process.BeginOutputReadLine(); process.BeginErrorReadLine(); process.WaitForExit(); - if (co.Errors.Length > 0) + if (process.ExitCode != 0) { - throw new Exception($"Something went wrong executing the command: {Environment.NewLine + co.Errors}"); + throw new Exception($"Something went wrong executing the command:{Environment.NewLine}{argument}{Environment.NewLine}{co.Output}{co.Errors}"); } return co.Output; } @@ -120,18 +111,24 @@ private static string RunCmd(string argument) } class ConsoleOutput { - public string Output { get; set; } - public string Errors { get; set; } + public string Output { get; set; } = string.Empty; + public string Errors { get; set; } = string.Empty; public void OutputHandler(object sendingProcess, DataReceivedEventArgs outLine) { //* Do your stuff with the output (write to console/log/StringBuilder) - Output += (outLine.Data); + if (outLine.Data != null) + { + Output += outLine.Data + Environment.NewLine; + } } public void ErrorHandler(object sendingProcess, DataReceivedEventArgs outLine) { //* Do your stuff with the output (write to console/log/StringBuilder) - Errors += outLine.Data; + if (outLine.Data != null) + { + Errors += outLine.Data + Environment.NewLine; + } } } } diff --git a/error-reporting-csharp-dotnet-tool-tests/error-reporting-csharp-dotnet-tool-tests.csproj b/error-reporting-csharp-dotnet-tool-tests/error-reporting-csharp-dotnet-tool-tests.csproj index cdffd6d..551242e 100644 --- a/error-reporting-csharp-dotnet-tool-tests/error-reporting-csharp-dotnet-tool-tests.csproj +++ b/error-reporting-csharp-dotnet-tool-tests/error-reporting-csharp-dotnet-tool-tests.csproj @@ -2,7 +2,7 @@ Exe - net5.0 + net10.0 error_reporting_csharp_dotnet_tool_tests @@ -15,16 +15,12 @@ - - - - all - runtime; build; native; contentfiles; analyzers; buildtransitive - - + + all runtime; build; native; contentfiles; analyzers; buildtransitive + diff --git a/error-reporting-csharp-dotnet-tool/ExtractErrorCatalogInformation.cs b/error-reporting-csharp-dotnet-tool/ExtractErrorCatalogInformation.cs index 6901d4c..4beb773 100644 --- a/error-reporting-csharp-dotnet-tool/ExtractErrorCatalogInformation.cs +++ b/error-reporting-csharp-dotnet-tool/ExtractErrorCatalogInformation.cs @@ -67,8 +67,8 @@ private static async Task ExtractExaErrorUsage(string projectPath, ErrorCodeColl using (var workspace = MSBuildWorkspace.Create()) { - // Print message for WorkspaceFailed event to help diagnosing project load failures. - workspace.WorkspaceFailed += (o, e) => Console.WriteLine(e.Diagnostic.Kind + " : " + e.Diagnostic.Message); + // Print workspace failures to help diagnose project load problems. + workspace.RegisterWorkspaceFailedHandler(e => Console.WriteLine(e.Diagnostic.Kind + " : " + e.Diagnostic.Message)); Console.WriteLine($"Loading project '{projectPath}'"); diff --git a/error-reporting-csharp-dotnet-tool/error-reporting-csharp-dotnet-tool.csproj b/error-reporting-csharp-dotnet-tool/error-reporting-csharp-dotnet-tool.csproj index 97dafa8..d1fcd85 100644 --- a/error-reporting-csharp-dotnet-tool/error-reporting-csharp-dotnet-tool.csproj +++ b/error-reporting-csharp-dotnet-tool/error-reporting-csharp-dotnet-tool.csproj @@ -2,7 +2,7 @@ Exe - net5.0 + net10.0 error_reporting_csharp_dotnet_tool true @@ -18,17 +18,20 @@ - - - - - - + + + compile; build; native; contentfiles; analyzers; buildtransitive + + + + + + all runtime; build; native; contentfiles; analyzers; buildtransitive - - + + diff --git a/print_package_path.py b/print_package_path.py deleted file mode 100644 index 7f102fb..0000000 --- a/print_package_path.py +++ /dev/null @@ -1,14 +0,0 @@ -import re - - -def print_package_path(): - with open('packageoutput', 'r') as file: - packageoutput = file.read() - x = re.search("(?<= Successfully created package ')[\\w\\:\\\\\\-\\.]*(?=')", packageoutput) - print(x.group()) - - -# Press the green button in the gutter to run the script. -if __name__ == '__main__': - print_package_path() -