fix(929): remove altcover imports, correct SVGControl binding redirects, pass client-id to the repair workflow token step - #949
Merged
Conversation
…ive minor-audit folder with acceptance criteria Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com Claude-Session: https://claude.ai/code/session_01KoweznWqwJTkNCf6756FoF
…the pre-existing analyzer package gap Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com Claude-Session: https://claude.ai/code/session_01KoweznWqwJTkNCf6756FoF
Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com Claude-Session: https://claude.ai/code/session_01KNZiXntshsLY8vqqCHUvHm
…consistency-residuals-929
…bsoleted back-fill marked N/A, P1-T13 removed, PoshQC and CI-sourced PowerShell gates) Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com Claude-Session: https://claude.ai/code/session_01N3r7uhChZ6XRKuQntGLpsG
… deltas R1 to R9, A1 and A2 Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
… delta D-1 Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
… client-id to the token action Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
…k-off Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
…consistency-residuals-929
…(0 blocking) Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
This was referenced Sep 30, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Suggested title
fix(929): remove altcover imports, correct SVGControl binding redirects, pass client-id to the repair workflow token step
Summary
Exists()-guarded altcoverImportelements fromQuickFiler.Test/QuickFiler.Test.csproj; no packages manifest declared the package, so the imports were silently skipped.SVGControl/app.configbinding redirects:Fizzlernow redirects to 1.3.1.0 andSystem.Runtime.CompilerServices.Unsafeto 6.0.3.0, matching the SVGControl project references and the restored assemblies..github/workflows/dependabot-repair.ymlfrom the deprecatedapp-idinput toclient-idonactions/create-github-app-token@v3; the secret nameDEPENDABOT_REPAIR_APP_IDis unchanged and now holds the App's Client ID..github/workflows/README.mdto instruct the maintainer to store the Client ID, not the numeric App ID.ConsistencyVerifier.Tests.ps1and a newRepositoryTreeConsistency.Tests.ps1with four tree tests (Import census, SVGControl redirects, workflow input, runbook secret name).Why
Issue 929 consolidates the residual package-manifest consistency defects: a project's files and its own
packages.configmust agree, binding redirects must name the assembly version that ships, and the repair workflow must use the non-deprecated token input. The repair script reconciles redirects only for packages it upgrades, so the pre-existing SVGControl drift was hand-corrected and observed read-only with the pureInvoke-BindingRedirectReconciliationfunction (pre-fix 1 repair per assembly, post-fix 0).What Changed
Build and configuration
QuickFiler.Test/QuickFiler.Test.csproj: two altcoverImportlines deleted (570 to 568 lines).SVGControl/app.config: twobindingRedirectlines corrected.CI workflow and documentation
.github/workflows/dependabot-repair.yml:client-idinput; header comment describes the Client ID secret..github/workflows/README.md: secret table row describes the Client ID.docs/features/active/2026-09-19-dependabot-fanout-and-ci-failing-nuget-upgrades-911/runbooks/github-app-installation-token.runbook.md: Part B heading, steps 10 and 22, and the YAML sample.PowerShell tooling and tests
scripts/dependencies/ConsistencyVerifier.psm1: comment-only update (line count unchanged at 499); no detection rule changed, because the absent-from-manifest detector already coversImportelements.tests/scripts/dependencies/ConsistencyVerifier.Tests.ps1: two Import-kind tests; stale fixture comments corrected.tests/scripts/dependencies/RepositoryTreeConsistency.Tests.ps1(new): four tests that read tracked files only and create nothing on disk.Evidence and audits
docs/features/active/2026-09-28-package-manifest-consistency-residuals-929/: atomic plan (revision 3.2), Phase 0 baseline, regression, QA-gate evidence, and the reduced-audit policy audit, code review and feature audit.Architecture / How It Fits Together
The new tree test calls
Find-PackageAbsentFromManifestfromConsistencyVerifier.psm1for every project directory that carries a manifest, so an unmanifestedImportanywhere in the tree now fails the Pester suite that CI already runs (_pester.yml). The workflow and runbook tests extract the secret name from the workflow and assert it in the runbook, so the two documents cannot drift apart silently.Verification
Completed (recorded in the feature folder evidence)
b96926588(run 36722780748): 379 passed, 0 failed (main baseline run 36666302259: 373); line coverage 94.51 percent (1721 of 1821), equal to baseline;ConsistencyVerifier.psm1158 covered, 2 missed, equal to baseline.HYGIENE Findings=0.Recommended
Backward Compatibility / Migration Notes
DEPENDABOT_REPAIR_APP_IDmust hold the GitHub App's Client ID once provisioned. The secret is not yet provisioned, so the token step already fails and this change requires no maintainer action to merge.Risks and Mitigations
b96926588failed one pre-existing concurrency test (QfcItemController_UiThreadDispatcherFixtureTests.Transaction_SecondCallerCannotInstallUntilTheFirstRestores), and one local iteration failed a different timing test (RemainingLoadActive_AcrossAsyncVoidFirstAwait_StaysTrueWhileLoaderProduces). This change edits no C# source and the altcover imports it removes were never resolved by a restore, so the compiled test assembly is unchanged; the reduced audit assessed both failures as not attributable to this change.Review Guide
SVGControl/app.configandQuickFiler.Test/QuickFiler.Test.csproj(four changed lines in total)..github/workflows/dependabot-repair.yml, the workflows README row, and the runbook.tests/scripts/dependencies/RepositoryTreeConsistency.Tests.ps1and the two new tests inConsistencyVerifier.Tests.ps1.Follow-ups
Not filed from this branch; listed for the coordinator.
*.csproj.bakcopies remain; two still contain the altcover token. Removal is a separate housekeeping change.dependabot-repair.ymlline 14 header comment is about 150 characters and could be re-wrapped.app.configfiles still redirect Fizzler to 1.3.0.0; already recorded indocs/features/potential/2026-08-04-stale-fizzler-and-unsafe-binding-redirects.md.workflow_run) remains to be confirmed.GitHub Auto-close
🤖 Generated with Claude Code