From 29f357589ac31551075e0e50e2109b28adcffc67 Mon Sep 17 00:00:00 2001 From: Tun Loakthar Date: Wed, 26 Feb 2025 13:37:05 +0000 Subject: [PATCH 1/9] Add security.md file --- SECURITY.md | 26 ++++++++++++++++++++++++++ 1 file changed, 26 insertions(+) create mode 100644 SECURITY.md diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..5c9e6f4 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,26 @@ +# Security + +If you believe you have found a new security vulnerability in this repository, please report it to us as follows. + +## Reporting Security Issues + +* Please do **not** report security vulnerabilities through public GitHub issues. + +* Please create a draft security advisory on the Github page: the reporting form is under `> Security > Advisories`. The URL is https://github.com/exasol/error-crawler-csharp/security/advisories/new. + +* If you prefer to email, please send your report to `infosec@exasol.com`. + +## Guidelines + +* When reporting a vulnerability, please include as much information as possible, including the complete steps to reproduce the issue. + +* Avoid sending us executables. + +* Feel free to include any script you wrote and used but avoid sending us scripts that download and run binaries. + +* We will prioritise reports that show how the exploits work in realistic environments. + +* We prefer all communications to be in English. + +* We do not offer financial rewards. We are happy to acknowledge your research publicly when possible. + From 860b1090247e292b15f5fd4eac7b747ae62e46ba Mon Sep 17 00:00:00 2001 From: Pieterjan Spoelders Date: Fri, 8 May 2026 15:51:54 +0200 Subject: [PATCH 2/9] Update dependencies - update targeted dotnet version - update dependencies - update to test logic --- .../Tests.cs | 49 +++++++++---------- ...-reporting-csharp-dotnet-tool-tests.csproj | 12 ++--- .../ExtractErrorCatalogInformation.cs | 4 +- .../error-reporting-csharp-dotnet-tool.csproj | 21 ++++---- 4 files changed, 41 insertions(+), 45 deletions(-) diff --git a/error-reporting-csharp-dotnet-tool-tests/Tests.cs b/error-reporting-csharp-dotnet-tool-tests/Tests.cs index 6f94bfe..421d62a 100644 --- a/error-reporting-csharp-dotnet-tool-tests/Tests.cs +++ b/error-reporting-csharp-dotnet-tool-tests/Tests.cs @@ -35,31 +35,22 @@ public void IntegrationTestNoProjectTag() } private static void PackageAndInstallTool() { - string output = RunCmd("cd ../../../.. && dotnet pack"); + RunCmd("cd ../../../.. && dotnet pack"); - string buildVersion = ExtractBuildVersionFromPackageOutput(output); - RunCmd($"cd ../../../.. && dotnet tool update -g --add-source .\\error-reporting-csharp-dotnet-tool\\nupkg\\ exasol-error-crawler --version {buildVersion}"); + string buildVersion = ExtractBuildVersionFromPackage(); + RunCmd($"cd ../../../.. && dotnet tool update -g --source .\\error-reporting-csharp-dotnet-tool\\nupkg\\ --source https://api.nuget.org/v3/index.json exasol-error-crawler --version {buildVersion}"); } - private static string ExtractBuildVersionFromPackageOutput(string output) + private static string ExtractBuildVersionFromPackage() { - string buildVersion = string.Empty; - string packagePathRegexStr = "(?<= Successfully created package ')[\\w\\:\\\\\\-\\.]*(?=')"; - Regex packagePathRegex = new Regex(packagePathRegexStr); - var packagePathMatch = packagePathRegex.Match(output); - if (packagePathMatch.Success) - { - string versionRegexStr = "(?<=crawler\\.)[\\w\\W]*(?=.nupkg)"; - Regex versionRegex = new Regex(versionRegexStr); - var versionMatch = versionRegex.Match(packagePathMatch.Value); - if (versionMatch.Success) - { - //https://stackoverflow.com/questions/19774155/returning-a-string-from-a-console-application - buildVersion = versionMatch.Value; - } - } + const string packageNamePrefix = "exasol-error-crawler."; + var packagePath = Directory.GetFiles(@"..\..\..\..\error-reporting-csharp-dotnet-tool\nupkg", $"{packageNamePrefix}*.nupkg") + .OrderByDescending(File.GetLastWriteTimeUtc) + .FirstOrDefault(); - return buildVersion; + Assert.False(string.IsNullOrEmpty(packagePath), "Could not find the packed exasol-error-crawler NuGet package."); + + return Path.GetFileNameWithoutExtension(packagePath).Substring(packageNamePrefix.Length); } private static void CheckResultingJSON() @@ -110,9 +101,9 @@ private static string RunCmd(string argument) process.BeginOutputReadLine(); process.BeginErrorReadLine(); process.WaitForExit(); - if (co.Errors.Length > 0) + if (process.ExitCode != 0) { - throw new Exception($"Something went wrong executing the command: {Environment.NewLine + co.Errors}"); + throw new Exception($"Something went wrong executing the command:{Environment.NewLine}{argument}{Environment.NewLine}{co.Output}{co.Errors}"); } return co.Output; } @@ -120,18 +111,24 @@ private static string RunCmd(string argument) } class ConsoleOutput { - public string Output { get; set; } - public string Errors { get; set; } + public string Output { get; set; } = string.Empty; + public string Errors { get; set; } = string.Empty; public void OutputHandler(object sendingProcess, DataReceivedEventArgs outLine) { //* Do your stuff with the output (write to console/log/StringBuilder) - Output += (outLine.Data); + if (outLine.Data != null) + { + Output += outLine.Data + Environment.NewLine; + } } public void ErrorHandler(object sendingProcess, DataReceivedEventArgs outLine) { //* Do your stuff with the output (write to console/log/StringBuilder) - Errors += outLine.Data; + if (outLine.Data != null) + { + Errors += outLine.Data + Environment.NewLine; + } } } } diff --git a/error-reporting-csharp-dotnet-tool-tests/error-reporting-csharp-dotnet-tool-tests.csproj b/error-reporting-csharp-dotnet-tool-tests/error-reporting-csharp-dotnet-tool-tests.csproj index cdffd6d..551242e 100644 --- a/error-reporting-csharp-dotnet-tool-tests/error-reporting-csharp-dotnet-tool-tests.csproj +++ b/error-reporting-csharp-dotnet-tool-tests/error-reporting-csharp-dotnet-tool-tests.csproj @@ -2,7 +2,7 @@ Exe - net5.0 + net10.0 error_reporting_csharp_dotnet_tool_tests @@ -15,16 +15,12 @@ - - - - all - runtime; build; native; contentfiles; analyzers; buildtransitive - - + + all runtime; build; native; contentfiles; analyzers; buildtransitive + diff --git a/error-reporting-csharp-dotnet-tool/ExtractErrorCatalogInformation.cs b/error-reporting-csharp-dotnet-tool/ExtractErrorCatalogInformation.cs index 6901d4c..4beb773 100644 --- a/error-reporting-csharp-dotnet-tool/ExtractErrorCatalogInformation.cs +++ b/error-reporting-csharp-dotnet-tool/ExtractErrorCatalogInformation.cs @@ -67,8 +67,8 @@ private static async Task ExtractExaErrorUsage(string projectPath, ErrorCodeColl using (var workspace = MSBuildWorkspace.Create()) { - // Print message for WorkspaceFailed event to help diagnosing project load failures. - workspace.WorkspaceFailed += (o, e) => Console.WriteLine(e.Diagnostic.Kind + " : " + e.Diagnostic.Message); + // Print workspace failures to help diagnose project load problems. + workspace.RegisterWorkspaceFailedHandler(e => Console.WriteLine(e.Diagnostic.Kind + " : " + e.Diagnostic.Message)); Console.WriteLine($"Loading project '{projectPath}'"); diff --git a/error-reporting-csharp-dotnet-tool/error-reporting-csharp-dotnet-tool.csproj b/error-reporting-csharp-dotnet-tool/error-reporting-csharp-dotnet-tool.csproj index 97dafa8..d1fcd85 100644 --- a/error-reporting-csharp-dotnet-tool/error-reporting-csharp-dotnet-tool.csproj +++ b/error-reporting-csharp-dotnet-tool/error-reporting-csharp-dotnet-tool.csproj @@ -2,7 +2,7 @@ Exe - net5.0 + net10.0 error_reporting_csharp_dotnet_tool true @@ -18,17 +18,20 @@ - - - - - - + + + compile; build; native; contentfiles; analyzers; buildtransitive + + + + + + all runtime; build; native; contentfiles; analyzers; buildtransitive - - + + From ae7e786910a1cbf5ed6c222c3d881b9f749421c7 Mon Sep 17 00:00:00 2001 From: Pieterjan Spoelders Date: Fri, 8 May 2026 15:55:32 +0200 Subject: [PATCH 3/9] Changes to workflows - target dotnet 10 --- .github/workflows/dotnet.yml | 10 ++++------ .github/workflows/publish-on-tag.yml | 4 ++-- 2 files changed, 6 insertions(+), 8 deletions(-) diff --git a/.github/workflows/dotnet.yml b/.github/workflows/dotnet.yml index b9b165e..0cd6c86 100644 --- a/.github/workflows/dotnet.yml +++ b/.github/workflows/dotnet.yml @@ -1,10 +1,8 @@ name: .NET on: - push: - branches: [ ] pull_request: - branches: [ ] + branches: [ main ] jobs: build: @@ -13,10 +11,10 @@ jobs: steps: - uses: actions/checkout@v2 - - name: Setup .NET - uses: actions/setup-dotnet@v1 + - name: Setup .NET 10 + uses: actions/setup-dotnet@v5 with: - dotnet-version: 5.0.x + dotnet-version: 10.0.x - name: Add Exasol GH Nuget Source run: dotnet nuget add source --username exa-ci-1 --password ${{ secrets.GITHUB_TOKEN }} --store-password-in-clear-text --name github "https://nuget.pkg.github.com/EXASOL/index.json" - name: Restore dependencies diff --git a/.github/workflows/publish-on-tag.yml b/.github/workflows/publish-on-tag.yml index c6c2370..0932fe8 100644 --- a/.github/workflows/publish-on-tag.yml +++ b/.github/workflows/publish-on-tag.yml @@ -15,10 +15,10 @@ jobs: steps: - uses: actions/checkout@v2 - - name: Setup .NET 5 + - name: Setup .NET 10 uses: actions/setup-dotnet@v1 with: - dotnet-version: 5.0.x + dotnet-version: 10.0.x - name: NuGet Add Source run: dotnet nuget add source --username exa-ci-1 --password ${{ secrets.GITHUB_TOKEN }} --store-password-in-clear-text --name github "https://nuget.pkg.github.com/EXASOL/index.json" From b7743acf293ac4304e1bb57baf3ef13d832e4db9 Mon Sep 17 00:00:00 2001 From: Pieterjan Spoelders Date: Tue, 23 Jun 2026 12:10:12 +0200 Subject: [PATCH 4/9] Update checkout action --- .github/workflows/dotnet.yml | 2 +- .github/workflows/publish-on-tag.yml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/dotnet.yml b/.github/workflows/dotnet.yml index 0cd6c86..298d5b3 100644 --- a/.github/workflows/dotnet.yml +++ b/.github/workflows/dotnet.yml @@ -10,7 +10,7 @@ jobs: runs-on: windows-latest steps: - - uses: actions/checkout@v2 + - uses: actions/checkout@v7 - name: Setup .NET 10 uses: actions/setup-dotnet@v5 with: diff --git a/.github/workflows/publish-on-tag.yml b/.github/workflows/publish-on-tag.yml index 0932fe8..10da89e 100644 --- a/.github/workflows/publish-on-tag.yml +++ b/.github/workflows/publish-on-tag.yml @@ -13,7 +13,7 @@ jobs: runs-on: windows-latest steps: - - uses: actions/checkout@v2 + - uses: actions/checkout@v7 - name: Setup .NET 10 uses: actions/setup-dotnet@v1 From da5094cda27fa1e241ef44dcb5e07f53ce5e8bc1 Mon Sep 17 00:00:00 2001 From: Pieterjan Spoelders Date: Tue, 23 Jun 2026 13:33:59 +0200 Subject: [PATCH 5/9] simplify release workflow, remove python script --- .github/workflows/publish-on-tag.yml | 33 ++++++++++++++-------------- print_package_path.py | 14 ------------ 2 files changed, 17 insertions(+), 30 deletions(-) delete mode 100644 print_package_path.py diff --git a/.github/workflows/publish-on-tag.yml b/.github/workflows/publish-on-tag.yml index 10da89e..968c09d 100644 --- a/.github/workflows/publish-on-tag.yml +++ b/.github/workflows/publish-on-tag.yml @@ -1,14 +1,16 @@ -name: publish to GH +name: Publish to GitHub Packages on: push: - branches: - - "!*" tags: - "*" +permissions: + contents: read + packages: write + jobs: - build: + publish: runs-on: windows-latest @@ -16,26 +18,25 @@ jobs: - uses: actions/checkout@v7 - name: Setup .NET 10 - uses: actions/setup-dotnet@v1 + uses: actions/setup-dotnet@v5 with: dotnet-version: 10.0.x - - name: NuGet Add Source + - name: Add Exasol GitHub NuGet source run: dotnet nuget add source --username exa-ci-1 --password ${{ secrets.GITHUB_TOKEN }} --store-password-in-clear-text --name github "https://nuget.pkg.github.com/EXASOL/index.json" - + - name: Restore dependencies run: dotnet restore + - name: Build - run: dotnet build --no-restore + run: dotnet build --configuration Release --no-restore + - name: Test - run: dotnet test --no-build --verbosity normal - - name: pack - run: dotnet pack --configuration Release > packageoutput + run: dotnet test --configuration Release --no-build --verbosity normal - - name: set variable - run: $cmdOutput = python .\print_package_path.py ; $cmdOutput; echo "NPPATH=$cmdOutput" | Out-File -FilePath $Env:GITHUB_ENV -Encoding utf-8 -Append; + - name: Pack + run: dotnet pack ./error-reporting-csharp-dotnet-tool/error-reporting-csharp-dotnet-tool.csproj --configuration Release --no-build --output ./artifacts/packages - # https://stackoverflow.com/questions/57889719/how-to-push-nuget-package-in-github-actions - - name: NuGet Push to GH NuGet - run: dotnet nuget push ${{ env.NPPATH }} -s "github" --api-key ${{ secrets.GITHUB_TOKEN }} + - name: Push to GitHub NuGet + run: dotnet nuget push ./artifacts/packages/*.nupkg --source "github" --api-key ${{ secrets.GITHUB_TOKEN }} --skip-duplicate diff --git a/print_package_path.py b/print_package_path.py deleted file mode 100644 index 7f102fb..0000000 --- a/print_package_path.py +++ /dev/null @@ -1,14 +0,0 @@ -import re - - -def print_package_path(): - with open('packageoutput', 'r') as file: - packageoutput = file.read() - x = re.search("(?<= Successfully created package ')[\\w\\:\\\\\\-\\.]*(?=')", packageoutput) - print(x.group()) - - -# Press the green button in the gutter to run the script. -if __name__ == '__main__': - print_package_path() - From 3ebea906eb4ef4987d9df1c57df4970418f208e1 Mon Sep 17 00:00:00 2001 From: Pieterjan Spoelders Date: Wed, 24 Jun 2026 06:32:36 +0200 Subject: [PATCH 6/9] Add version doc --- README.md | 1 + doc/changes/changelog.md | 3 +++ doc/changes/changes_0.5.0.md | 10 ++++++++++ 3 files changed, 14 insertions(+) create mode 100644 doc/changes/changelog.md create mode 100644 doc/changes/changes_0.5.0.md diff --git a/README.md b/README.md index 7ca6bcd..edb3dcb 100644 --- a/README.md +++ b/README.md @@ -46,5 +46,6 @@ The short tag is the only parameter required, ## Additional Information +* [Changelog](doc/changes/changelog.md) * [License](LICENSE) diff --git a/doc/changes/changelog.md b/doc/changes/changelog.md new file mode 100644 index 0000000..f74578d --- /dev/null +++ b/doc/changes/changelog.md @@ -0,0 +1,3 @@ +# Changes + +* [0.5.0](changes_0.5.0.md) diff --git a/doc/changes/changes_0.5.0.md b/doc/changes/changes_0.5.0.md new file mode 100644 index 0000000..c427eec --- /dev/null +++ b/doc/changes/changes_0.5.0.md @@ -0,0 +1,10 @@ +# error-crawler-csharp 0.5.0, released 2026-06-24 + +Code Name: Release Automation + +## Features / Enhancements + +* Updated the GitHub Packages publish workflow for tag-based releases. +* Removed the Python helper that parsed `dotnet pack` output. +* Updated the target .NET framework and refreshed dependencies. +* Added release documentation and a changelog. From 2cf7634eb4fa4aa58a3c646f3fc44ffa30ec79cb Mon Sep 17 00:00:00 2001 From: Pieterjan Spoelders Date: Wed, 24 Jun 2026 07:15:49 +0200 Subject: [PATCH 7/9] Changed version # --- doc/changes/changelog.md | 2 +- doc/changes/{changes_0.5.0.md => changes_1.0.0.md} | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) rename doc/changes/{changes_0.5.0.md => changes_1.0.0.md} (85%) diff --git a/doc/changes/changelog.md b/doc/changes/changelog.md index f74578d..e4dd4a8 100644 --- a/doc/changes/changelog.md +++ b/doc/changes/changelog.md @@ -1,3 +1,3 @@ # Changes -* [0.5.0](changes_0.5.0.md) +* [1.0.0](changes_1.0.0.md) diff --git a/doc/changes/changes_0.5.0.md b/doc/changes/changes_1.0.0.md similarity index 85% rename from doc/changes/changes_0.5.0.md rename to doc/changes/changes_1.0.0.md index c427eec..fd58f81 100644 --- a/doc/changes/changes_0.5.0.md +++ b/doc/changes/changes_1.0.0.md @@ -1,4 +1,4 @@ -# error-crawler-csharp 0.5.0, released 2026-06-24 +# error-crawler-csharp 1.0.0, released 2026-06-24 Code Name: Release Automation From a65cc8644d907035e3407dac929e5d0f74711dda Mon Sep 17 00:00:00 2001 From: Pieterjan Spoelders Date: Thu, 25 Jun 2026 10:14:05 +0200 Subject: [PATCH 8/9] add dependency update section --- doc/changes/changes_1.0.0.md | 25 ++++++++++++++++++++++++- 1 file changed, 24 insertions(+), 1 deletion(-) diff --git a/doc/changes/changes_1.0.0.md b/doc/changes/changes_1.0.0.md index fd58f81..d78d047 100644 --- a/doc/changes/changes_1.0.0.md +++ b/doc/changes/changes_1.0.0.md @@ -1,4 +1,4 @@ -# error-crawler-csharp 1.0.0, released 2026-06-24 +# error-crawler-csharp 1.0.0, released 2026-06-25 Code Name: Release Automation @@ -8,3 +8,26 @@ Code Name: Release Automation * Removed the Python helper that parsed `dotnet pack` output. * Updated the target .NET framework and refreshed dependencies. * Added release documentation and a changelog. + +## Dependency Updates + +### `error-reporting-csharp-dotnet-tool/error-reporting-csharp-dotnet-tool.csproj` + +* Updated `TargetFramework` from `net5.0` to `net10.0` +* Updated `CommandLineParser` from `2.8.0` to `2.9.1` +* Added `Microsoft.Build.Framework` version `18.4.0` +* Updated `Microsoft.Build.Locator` from `1.4.1` to `1.11.2` +* Updated `Microsoft.CodeAnalysis` from `4.0.1` to `5.3.0` +* Updated `Microsoft.CodeAnalysis.CSharp` from `4.0.1` to `5.3.0` +* Updated `Microsoft.CodeAnalysis.Workspaces.MSBuild` from `4.0.1` to `5.3.0` +* Updated `MinVer` from `2.5.0` to `7.0.0` +* Updated `Newtonsoft.Json` from `13.0.1` to `13.0.4` +* Updated `NJsonSchema` from `10.6.5` to `11.6.1` + +### `error-reporting-csharp-dotnet-tool-tests/error-reporting-csharp-dotnet-tool-tests.csproj` + +* Updated `TargetFramework` from `net5.0` to `net10.0` +* Updated `Microsoft.NET.Test.Sdk` from `17.0.0` to `18.5.1` +* Updated `xunit.runner.visualstudio` from `2.4.3` to `3.1.5` +* Removed `xunit.runner.console` version `2.4.1` +* Replaced `xunit` version `2.4.1` with `xunit.v3` version `3.2.2` From ced250f46af7595a8dd02d1278bfd7791a56fd06 Mon Sep 17 00:00:00 2001 From: Pieterjan Spoelders Date: Thu, 25 Jun 2026 10:33:56 +0200 Subject: [PATCH 9/9] fix push step --- .github/workflows/publish-on-tag.yml | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/.github/workflows/publish-on-tag.yml b/.github/workflows/publish-on-tag.yml index 968c09d..1f4a2d0 100644 --- a/.github/workflows/publish-on-tag.yml +++ b/.github/workflows/publish-on-tag.yml @@ -38,5 +38,14 @@ jobs: run: dotnet pack ./error-reporting-csharp-dotnet-tool/error-reporting-csharp-dotnet-tool.csproj --configuration Release --no-build --output ./artifacts/packages - name: Push to GitHub NuGet - run: dotnet nuget push ./artifacts/packages/*.nupkg --source "github" --api-key ${{ secrets.GITHUB_TOKEN }} --skip-duplicate + shell: pwsh + run: | + $packages = Get-ChildItem -Path ./artifacts/packages -Filter *.nupkg + if (-not $packages) { + throw "No NuGet packages found in ./artifacts/packages." + } + + foreach ($package in $packages) { + dotnet nuget push $package.FullName --source "github" --api-key ${{ secrets.GITHUB_TOKEN }} --skip-duplicate + }