Skip to content

Consolidate SDK CI and runtime contract adjustments - #84

Closed
AriusII wants to merge 9 commits into
mainfrom
sdk/local-main-consolidation
Closed

AriusII wants to merge 9 commits into
mainfrom
sdk/local-main-consolidation

Conversation

@AriusII

@AriusII AriusII commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Add an opt-in dependency-review job to the reusable CI workflow for non-draft pull requests.
  • Keep the dependency review result in the gate when it is enabled, while allowing repositories without GitHub Dependency graph support to run the rest of CI cleanly.
  • Preserve the intentional runtime lifecycle, Lua annotation inheritance, and ABI-related adjustments from the local SDK work.
  • Base the branch on the current merged main so previously merged changes are not replayed.

Validation

  • dotnet build CheatEngine.SDK.slnx -c Release --no-restore -warnaserror: passed with 0 warnings and 0 errors.
  • dotnet test --solution CheatEngine.SDK.slnx -c Release --no-build --fail-skips on: 2299 passed, 0 skipped, 0 failed.
  • Native MSVC x64 ABI fixture: 104 facts validated and compared successfully with managed layout measurements.
  • PR CI run: native bridge, ABI fixture, build, test matrix, pack, Native AOT probe, workflow lint, and gate all passed.
  • Dependency review is intentionally skipped while DEPENDENCY_REVIEW_ENABLED is not true; enabling it makes high-severity dependency findings gate the PR.

CodeRabbit

The latest CodeRabbit incremental review generated no actionable comments. Its previous two-test warning is resolved by commit 8b4c75e and the current local and remote test results are fully green.

No live Cheat Engine validation was run in this local environment.

Dependency review activation

Enable the repository variable DEPENDENCY_REVIEW_ENABLED=true only after GitHub Dependency graph is enabled for the repository. GitHub documents Dependency graph as a prerequisite for the Dependency Review Action: https://docs.github.com/en/code-security/tutorials/secure-your-dependencies/customize-dependency-review-action

Summary

  • Reworked CI around Debug and Release build-test jobs and reusable artifacts.
  • Added ABI fact validation and updated native ABI artifact flow.
  • Made Sonar analysis conditional and added explicit SONAR_TOKEN validation.
  • Restored inherited metadata behavior for Lua attributes and updated generator tests.
  • Preserved LuaRuntime behavior; changes only update Volatile access syntax.
  • Updated release automation to validate tags, publish the tested package with approval, and create release notes and attestations.
  • Added GitHub Actions test reporting and updated CI and release documentation.

Validation

  • Release build: 0 warnings and 0 errors.
  • Tests: 2,299 passed, 0 skipped, 0 failed.
  • Native MSVC x64 ABI validation: 104 facts matched.
  • PR CI passed for native bridge, ABI fixture, build, test matrix, packaging, Native AOT probe, workflow lint, and gate.
  • Live Cheat Engine validation was not run locally.

Add a pinned dependency-review job to the reusable CI workflow for non-draft pull requests. Include its result in the gate summary and require it only when the job is expected to run, so push and draft workflows remain valid while high-severity dependency changes fail the PR gate.
…place `Volatile` with `System.Threading.Volatile` static usage for Lua runtime lifecycle operations.
@coderabbitai

coderabbitai Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Repository: CheatEngineNet/CheatEngine.SDK/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: be51ca9c-a18d-4fb6-b3f2-066b75ac27e3

📥 Commits

Reviewing files that changed from the base of the PR and between 7c16180 and e40c99f.

📒 Files selected for processing (15)
  • .coderabbit.yaml
  • .github/PULL_REQUEST_TEMPLATE.md
  • .github/workflows/ci.yml
  • .github/workflows/main-ci.yml
  • .github/workflows/pull-request-ci.yml
  • .github/workflows/release.yml
  • .github/workflows/sonar.yml
  • CONTRIBUTING.md
  • CheatEngine.SDK.slnx
  • Directory.Packages.props
  • RELEASING.md
  • eng/Tests.props
  • libs/CheatEngine.SDK.Abi/README.md
  • tests/CheatEngine.SDK.Abi.Tests/README.md
  • tests/native-abi-fixture/README.md

Warning

This pull request changes a CodeRabbit configuration file. Because it comes from a fork or its author is not a repository collaborator, reviews use only the configuration from the target branch. The proposed configuration will take effect after it is merged.

📝 Walkthrough

Walkthrough

The workflows add optional dependency-review gating, enable coverage collection, and remove Sonar secret and job usage. Lua class, marshaller, and property attributes now use default inheritance behavior, with updated generator tests. LuaRuntime uses statically imported volatile methods. Repository guidance, import ordering, and analyzer suppression formatting were also updated.

Priority: ⬇️ Low

Merge Risk: 🟠 High · up to 7c161

Main and pull-request CI can fail at the required Sonar gate. Restore trusted authentication and fork-safe skipping before merging.


Comment @coderabbitai help to get the list of available commands.

Restore the ABI alignment probe prefix so native MSVC fixture facts match managed x64 measurements. Align Lua annotation tests and documentation with the intentional framework-default inheritance contract. Make dependency review opt-in until GitHub Dependency graph is enabled, keep it blocking when enabled, and upgrade the pinned action to v5.
Delete the Sonar reusable workflow and remove its secret, coverage, and gate wiring from the base CI path. Keep pull requests focused on the repository-owned build, tests, packaging, Native AOT, dependency review, workflow lint, and final gate. Remove the now-unused Microsoft Testing Platform coverage extension and align CodeRabbit workflow guidance with the remaining pipeline.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to GitHub limitations.

⚠️ Outside diff range comments (1)

🟠 Major · Restore authenticated Sonar execution. · sonar.yml:165

.github/workflows/sonar.yml:165
🩺 Stability & Availability | 🟠 Major | 🏗️ Heavy lift

Restore authenticated Sonar execution.

main-ci.yml and pull-request-ci.yml both enable coverage, and ci.yml still invokes sonar.yml. The Sonar workflow declares no SONAR_TOKEN secret and passes no token to dotnet-sonarscanner begin or end. SonarQube Cloud can reject this unauthenticated analysis, causing the Sonar job and CI gate to fail.

Forward SONAR_TOKEN through the reusable workflows only for trusted callers. Pass it to both scanner commands. Skip Sonar when the token is unavailable, including forked pull requests. Update the gate so it does not require a skipped Sonar job when the token is unavailable; it currently requires Sonar whenever coverage is enabled.


ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: CheatEngineNet/CheatEngine.SDK/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: cb3ce5b5-c840-4c87-8d5b-5565742b39d6

📥 Commits

Reviewing files that changed from the base of the PR and between 431a6ca and 7c16180.

📒 Files selected for processing (4)
  • .github/workflows/ci.yml
  • .github/workflows/main-ci.yml
  • .github/workflows/pull-request-ci.yml
  • .github/workflows/sonar.yml
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • CheatEngineNet/CheatEngine.Client (manual)

Included review availability: Your plan provides up to 10 included reviews per hour; 6 remain after this review.

Build and test the solution once per configuration, pack the tested Release build, reuse the native bridge, ABI facts and coverage artifacts, restore the Sonar token with fork and Dependabot guards, run actionlint on every event, and evaluate the gate generically over all jobs.
Release the nuget-package artifact built and tested on the tag, behind the nuget environment approval, with CHANGELOG release notes, a nuget.org duplicate guard and attestation after the push.
Use the assertive profile with advisory pre-merge checks, simplify the pull request template, and describe the CI, squash merges and releases in CONTRIBUTING.
@AriusII AriusII closed this Sep 22, 2026
@AriusII
AriusII deleted the sdk/local-main-consolidation branch September 22, 2026 18:54
@AriusII
AriusII restored the sdk/local-main-consolidation branch September 22, 2026 18:55
@AriusII
AriusII deleted the sdk/local-main-consolidation branch September 22, 2026 18:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant