Conversation
Add a pinned dependency-review job to the reusable CI workflow for non-draft pull requests. Include its result in the gate summary and require it only when the job is expected to run, so push and draft workflows remain valid while high-severity dependency changes fail the PR gate.
…place `Volatile` with `System.Threading.Volatile` static usage for Lua runtime lifecycle operations.
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configurationConfiguration used: Repository: CheatEngineNet/CheatEngine.SDK/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (15)
Warning This pull request changes a CodeRabbit configuration file. Because it comes from a fork or its author is not a repository collaborator, reviews use only the configuration from the target branch. The proposed configuration will take effect after it is merged. 📝 WalkthroughWalkthroughThe workflows add optional dependency-review gating, enable coverage collection, and remove Sonar secret and job usage. Lua class, marshaller, and property attributes now use default inheritance behavior, with updated generator tests. Priority: ⬇️ Low Merge Risk: 🟠 High · up to Main and pull-request CI can fail at the required Sonar gate. Restore trusted authentication and fork-safe skipping before merging. Comment |
Restore the ABI alignment probe prefix so native MSVC fixture facts match managed x64 measurements. Align Lua annotation tests and documentation with the intentional framework-default inheritance contract. Make dependency review opt-in until GitHub Dependency graph is enabled, keep it blocking when enabled, and upgrade the pinned action to v5.
Delete the Sonar reusable workflow and remove its secret, coverage, and gate wiring from the base CI path. Keep pull requests focused on the repository-owned build, tests, packaging, Native AOT, dependency review, workflow lint, and final gate. Remove the now-unused Microsoft Testing Platform coverage extension and align CodeRabbit workflow guidance with the remaining pipeline.
This reverts commit 431a6ca.
There was a problem hiding this comment.
Caution
Some comments are outside the diff and can’t be posted inline due to GitHub limitations.
🟠 Major · Restore authenticated Sonar execution. · sonar.yml:165
.github/workflows/sonar.yml:165
🩺 Stability & Availability | 🟠 Major | 🏗️ Heavy liftRestore authenticated Sonar execution.
main-ci.ymlandpull-request-ci.ymlboth enable coverage, andci.ymlstill invokessonar.yml. The Sonar workflow declares noSONAR_TOKENsecret and passes no token todotnet-sonarscanner beginorend. SonarQube Cloud can reject this unauthenticated analysis, causing the Sonar job and CI gate to fail.Forward
SONAR_TOKENthrough the reusable workflows only for trusted callers. Pass it to both scanner commands. Skip Sonar when the token is unavailable, including forked pull requests. Update the gate so it does not require a skipped Sonar job when the token is unavailable; it currently requires Sonar whenever coverage is enabled.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository: CheatEngineNet/CheatEngine.SDK/.coderabbit.yaml
Review profile: CHILL
Plan: Advanced
Run ID: cb3ce5b5-c840-4c87-8d5b-5565742b39d6
📒 Files selected for processing (4)
.github/workflows/ci.yml.github/workflows/main-ci.yml.github/workflows/pull-request-ci.yml.github/workflows/sonar.yml
🔗 Linked repositories identified
CodeRabbit considers these linked repositories for cross-repo context during reviews:
CheatEngineNet/CheatEngine.Client(manual)
Included review availability: Your plan provides up to 10 included reviews per hour; 6 remain after this review.
Build and test the solution once per configuration, pack the tested Release build, reuse the native bridge, ABI facts and coverage artifacts, restore the Sonar token with fork and Dependabot guards, run actionlint on every event, and evaluate the gate generically over all jobs.
Release the nuget-package artifact built and tested on the tag, behind the nuget environment approval, with CHANGELOG release notes, a nuget.org duplicate guard and attestation after the push.
Use the assertive profile with advisory pre-merge checks, simplify the pull request template, and describe the CI, squash merges and releases in CONTRIBUTING.
Summary
mainso previously merged changes are not replayed.Validation
dotnet build CheatEngine.SDK.slnx -c Release --no-restore -warnaserror: passed with 0 warnings and 0 errors.dotnet test --solution CheatEngine.SDK.slnx -c Release --no-build --fail-skips on: 2299 passed, 0 skipped, 0 failed.DEPENDENCY_REVIEW_ENABLEDis nottrue; enabling it makes high-severity dependency findings gate the PR.CodeRabbit
The latest CodeRabbit incremental review generated no actionable comments. Its previous two-test warning is resolved by commit
8b4c75eand the current local and remote test results are fully green.No live Cheat Engine validation was run in this local environment.
Dependency review activation
Enable the repository variable
DEPENDENCY_REVIEW_ENABLED=trueonly after GitHub Dependency graph is enabled for the repository. GitHub documents Dependency graph as a prerequisite for the Dependency Review Action: https://docs.github.com/en/code-security/tutorials/secure-your-dependencies/customize-dependency-review-actionSummary
build-testjobs and reusable artifacts.SONAR_TOKENvalidation.LuaRuntimebehavior; changes only updateVolatileaccess syntax.Validation