You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Consolidates #912 with the remaining parts of #914. PRs #920 and #921 fixed 8 of the 10 stale binding redirects and the Invoke-ProjectConsistencyRepair fallback defect. All remaining items break one invariant: a project's files and its own packages.config must agree, and the repair workflow that maintains them must be runnable.
Bug: quickfiler-test-imports-altcover-absent-from-manifest #912:QuickFiler.Test/QuickFiler.Test.csproj lines 8 and 535 import altcover.8.6.45 build assets. No packages.config declares altcover, so the imports are silently skipped by their Exists() guard.
Bug: dependabot-repair-deferred-credential-criteria-and-residuals (follow-up to #911) #914 sub-item 1 (verification only, requires the maintainer): AC18, AC19 and AC20 of Bug: dependabot-fanout-and-ci-failing-nuget-upgrades #911 can only be exercised after a GitHub App credential is provisioned. The runbook is at docs/features/active/2026-09-19-dependabot-fanout-and-ci-failing-nuget-upgrades-911/runbooks/github-app-installation-token.runbook.md. The secret store is also unconfirmed: a Dependabot-triggered workflow_run may read only Dependabot secrets. None of this is a merge gate for items 1 to 3.
Command/flags used: nuget restore TaskMaster.sln from cold; static inspection on main at 177b6d78e
Data source or fixture: QuickFiler.Test/QuickFiler.Test.csproj, QuickFiler.Test/packages.config, SVGControl/app.config, SVGControl/packages.config, .github/workflows/dependabot-repair.yml
Steps to Reproduce
git grep -n altcover -- "*.csproj" "*packages.config" finds two imports and no manifest entry.
Compare the SVGControl/app.configbindingRedirect newVersion values for Fizzler and System.Runtime.CompilerServices.Unsafe with the referenced assembly versions.
Read dependabot-repair.yml:51.
Expected Behavior
Every ..\packages\ import corresponds to a manifest entry.
Every binding redirect names the assembly version that actually ships.
The repair workflow uses the non-deprecated input.
Summary
Consolidates #912 with the remaining parts of #914. PRs #920 and #921 fixed 8 of the 10 stale binding redirects and the
Invoke-ProjectConsistencyRepairfallback defect. All remaining items break one invariant: a project's files and its ownpackages.configmust agree, and the repair workflow that maintains them must be runnable.QuickFiler.Test/QuickFiler.Test.csprojlines 8 and 535 importaltcover.8.6.45build assets. Nopackages.configdeclaresaltcover, so the imports are silently skipped by theirExists()guard.SVGControl/app.configare still stale:Fizzlerredirects to 1.3.0.0, but the reference and the restored package are 1.3.1.0.System.Runtime.CompilerServices.Unsaferedirects to 6.0.2.0, but the reference and the restored package are 6.0.3.0..github/workflows/dependabot-repair.yml:51passes the deprecatedapp-idinput toactions/create-github-app-token@v3. It should passclient-id, and the runbook should say to store the App's Client ID.docs/features/active/2026-09-19-dependabot-fanout-and-ci-failing-nuget-upgrades-911/runbooks/github-app-installation-token.runbook.md. The secret store is also unconfirmed: a Dependabot-triggeredworkflow_runmay read only Dependabot secrets. None of this is a merge gate for items 1 to 3.Environment
nuget restore TaskMaster.slnfrom cold; static inspection onmainat177b6d78eQuickFiler.Test/QuickFiler.Test.csproj,QuickFiler.Test/packages.config,SVGControl/app.config,SVGControl/packages.config,.github/workflows/dependabot-repair.ymlSteps to Reproduce
git grep -n altcover -- "*.csproj" "*packages.config"finds two imports and no manifest entry.SVGControl/app.configbindingRedirect newVersionvalues forFizzlerandSystem.Runtime.CompilerServices.Unsafewith the referenced assembly versions.dependabot-repair.yml:51.Expected Behavior
..\packages\import corresponds to a manifest entry.Actual Behavior
As listed in the Summary.
Logs / Screenshots
Mint an installation tokenwith the deprecation warning forapp-id(see the Bug: dependabot-repair-deferred-credential-criteria-and-residuals (follow-up to #911) #914 comment of 2026-09-26).Impact / Severity
Source
From: docs/features/potential/2026-09-28-package-manifest-consistency-residuals.md