Skip to content

Bug: package-manifest-consistency-residuals #929

Description

@drmoisan
  • Work Mode: minor-audit

Summary

Consolidates #912 with the remaining parts of #914. PRs #920 and #921 fixed 8 of the 10 stale binding redirects and the Invoke-ProjectConsistencyRepair fallback defect. All remaining items break one invariant: a project's files and its own packages.config must agree, and the repair workflow that maintains them must be runnable.

  1. Bug: quickfiler-test-imports-altcover-absent-from-manifest #912: QuickFiler.Test/QuickFiler.Test.csproj lines 8 and 535 import altcover.8.6.45 build assets. No packages.config declares altcover, so the imports are silently skipped by their Exists() guard.
  2. Bug: dependabot-repair-deferred-credential-criteria-and-residuals (follow-up to #911) #914 sub-item 3 residual: two binding redirects in SVGControl/app.config are still stale:
    • Fizzler redirects to 1.3.0.0, but the reference and the restored package are 1.3.1.0.
    • System.Runtime.CompilerServices.Unsafe redirects to 6.0.2.0, but the reference and the restored package are 6.0.3.0.
  3. Bug: dependabot-repair-deferred-credential-criteria-and-residuals (follow-up to #911) #914 comment item 1: .github/workflows/dependabot-repair.yml:51 passes the deprecated app-id input to actions/create-github-app-token@v3. It should pass client-id, and the runbook should say to store the App's Client ID.
  4. Bug: dependabot-repair-deferred-credential-criteria-and-residuals (follow-up to #911) #914 sub-item 1 (verification only, requires the maintainer): AC18, AC19 and AC20 of Bug: dependabot-fanout-and-ci-failing-nuget-upgrades #911 can only be exercised after a GitHub App credential is provisioned. The runbook is at docs/features/active/2026-09-19-dependabot-fanout-and-ci-failing-nuget-upgrades-911/runbooks/github-app-installation-token.runbook.md. The secret store is also unconfirmed: a Dependabot-triggered workflow_run may read only Dependabot secrets. None of this is a merge gate for items 1 to 3.

Environment

  • OS/version: Windows 11 Pro 10.0.26200
  • Python version: not applicable (.NET Framework 4.8.1 packages.config projects, GitHub Actions)
  • Command/flags used: nuget restore TaskMaster.sln from cold; static inspection on main at 177b6d78e
  • Data source or fixture: QuickFiler.Test/QuickFiler.Test.csproj, QuickFiler.Test/packages.config, SVGControl/app.config, SVGControl/packages.config, .github/workflows/dependabot-repair.yml

Steps to Reproduce

  1. git grep -n altcover -- "*.csproj" "*packages.config" finds two imports and no manifest entry.
  2. Compare the SVGControl/app.config bindingRedirect newVersion values for Fizzler and System.Runtime.CompilerServices.Unsafe with the referenced assembly versions.
  3. Read dependabot-repair.yml:51.

Expected Behavior

  • Every ..\packages\ import corresponds to a manifest entry.
  • Every binding redirect names the assembly version that actually ships.
  • The repair workflow uses the non-deprecated input.

Actual Behavior

As listed in the Summary.

Logs / Screenshots

Impact / Severity

  • Blocker
  • High
  • Medium
  • Low

Source

From: docs/features/potential/2026-09-28-package-manifest-consistency-residuals.md

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions