Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
202 commits
Select commit Hold shift + click to select a range
0a03dac
Apply repository formatting
AriusII Sep 22, 2026
4c833c5
Scaffold repository tests and shared package versions
AriusII Sep 22, 2026
2d7a01a
Declare CRLF line endings in .editorconfig
AriusII Sep 22, 2026
fc60165
Format the projects that live outside the solution
AriusII Sep 22, 2026
d8f6a87
Remove orphaned Python validators and their tests
AriusII Sep 22, 2026
babcb0a
Add the documentation index and placeholder pages
AriusII Sep 22, 2026
eab80f2
Re-point links to the retired documentations tree
AriusII Sep 22, 2026
506014a
Neutralize documentation claims without current evidence
AriusII Sep 22, 2026
0cde9a6
Add documentation integrity tests
AriusII Sep 22, 2026
2ebb0fa
Pin the .NET SDK and the code analysis level
AriusII Sep 22, 2026
5541dd7
Make the NuGet audit policy explicit
AriusII Sep 22, 2026
bcf96be
Track the public API of the shipping libraries
AriusII Sep 22, 2026
fdb6131
Validate the package against CheatEngine.SDK 1.0.0 on the 2.0 line
AriusII Sep 22, 2026
4860a65
Embed an SPDX SBOM and repository metadata in the package
AriusII Sep 22, 2026
d3b00b3
Add the lock-file regeneration script
AriusII Sep 22, 2026
ad46bd4
Commit NuGet lock files for every project
AriusII Sep 22, 2026
59ac04a
Force the verification restores of the lock-file script
AriusII Sep 22, 2026
b4c5b80
Drop the ineffective SBOM verbosity setting
AriusII Sep 22, 2026
0fcf298
Compile the CE 7.7 live probe with the solution
AriusII Sep 22, 2026
5876f6e
Add Checkpoint B hooks to the CE 7.7 live probe
AriusII Sep 22, 2026
72f2447
Add the v0 qualification schemas
AriusII Sep 22, 2026
1a93302
Validate qualification documents with a C# schema subset
AriusII Sep 22, 2026
c36890e
Publish the Cheat Engine support profiles
AriusII Sep 22, 2026
458b27e
Prove the receipt contract with accepted and refused samples
AriusII Sep 22, 2026
2e88b9d
Tag existing C0-C2 evidence with Qualification traits
AriusII Sep 22, 2026
823aa04
Add the Q01-Q48 qualification matrix
AriusII Sep 22, 2026
ae54db4
Add a deterministic x64/x86 qualification target
AriusII Sep 22, 2026
63adb07
Add the local exact-host qualification runner
AriusII Sep 23, 2026
8a03bf0
Map unhandled qualification runner errors to exit code 6
AriusII Sep 23, 2026
bf2961e
Document the local qualification protocol and runner
AriusII Sep 23, 2026
0a9f72c
Record the lock-file NuGet content hash in qualification receipts
AriusII Sep 23, 2026
1b02738
Count only Cheat Engine executables as another instance
AriusII Sep 23, 2026
08030bd
Group the qualification solution folders with the docs folders
AriusII Sep 23, 2026
6bcf689
Accept a comma-separated -Scenario list under pwsh -File
AriusII Sep 23, 2026
6ed6a06
Apply class-level Qualification traits to every test of the class
AriusII Sep 23, 2026
40f3d0b
Accept package-built plugin bundles in the runner closure check
AriusII Sep 23, 2026
52fc981
Require an observed removal of plugin A in the Q09 pass rules
AriusII Sep 23, 2026
a028592
Harden the runner work root, registry stage and operator prompts
AriusII Sep 23, 2026
f3a6e96
Pin the live probe status test to an injected fault decision
AriusII Sep 23, 2026
7b8fe3b
Declare the Q08 scope and the expected C3 outcome in the matrix
AriusII Sep 23, 2026
f02b20e
Check the repository locators of the support profile measurements
AriusII Sep 23, 2026
6d8487b
Guard the whole live probe callback thunk against exceptions
AriusII Sep 23, 2026
0ee3d65
Restore HKCU after a session when no other Cheat Engine runs
AriusII Sep 23, 2026
e8f523e
Refuse a malformed -HeadSha even without -PullRequest
AriusII Sep 23, 2026
27b041a
Require the index loadPlugin returns in the load pass-rule checks
AriusII Sep 23, 2026
21ca24d
Destroy the driver timer once and keep one event time base on resume
AriusII Sep 23, 2026
ad2bf05
Record the loaded bridge module in the live probe host profile
AriusII Sep 23, 2026
3292acf
Regenerate lock files after adding the qualification target
AriusII Sep 23, 2026
8baf1cb
Restore locked and pin runners in the SDK workflows
AriusII Sep 23, 2026
8645df8
Pin the bridge toolchain and prove path independence
AriusII Sep 23, 2026
4719202
Pack before testing and harden the test run
AriusII Sep 23, 2026
36e9b74
Merge coverage and enforce a per-assembly ratchet
AriusII Sep 23, 2026
9d07aab
Publish build info from the Release leg
AriusII Sep 23, 2026
2466b3d
Add zizmor, PSScriptAnalyzer and format checks
AriusII Sep 23, 2026
173813b
Review dependencies and verify lock files in CI
AriusII Sep 23, 2026
96b6b12
Require Sonar through the Gate expectation
AriusII Sep 23, 2026
c6cc9fe
Add the advisory client canary script
AriusII Sep 23, 2026
71b382a
Document the CI scripts and the workflow contract tests
AriusII Sep 23, 2026
d2df612
Reserve the artifact names of the advisory workflows
AriusII Sep 23, 2026
6b7fc57
Link the Sonar analysis from the job summary
AriusII Sep 23, 2026
4d6d742
Regenerate lock files after S-CI-PIPE
AriusII Sep 23, 2026
c59713f
Fix the live probe compile path after integrating S-CI-PIPE
AriusII Sep 23, 2026
41ef299
Harden Dependabot with cooldowns and SDK-implicit ignores
AriusII Sep 23, 2026
4ee334e
Enforce the pull request title and changelog policy
AriusII Sep 23, 2026
6a295bb
Add a security policy, code owners and compatibility issue forms
AriusII Sep 23, 2026
ec0c1d7
Add advisory CodeQL analysis for C#, C/C++ and workflows
AriusII Sep 23, 2026
09c1424
Add OpenSSF Scorecard and online zizmor audits
AriusII Sep 23, 2026
290361a
Submit the NuGet dependency graph from main
AriusII Sep 23, 2026
424c933
Add a weekly scheduled health workflow
AriusII Sep 23, 2026
af5b2cc
Add an idempotent repository settings script
AriusII Sep 23, 2026
a99b1d4
Accept the changelog waiver only on a line of its own
AriusII Sep 23, 2026
68d88d4
Annotate exempt Dependabot pull requests with a notice
AriusII Sep 23, 2026
badeec2
Accept prefixed forms of allowlisted imperative verbs
AriusII Sep 23, 2026
88ff038
Keep the canary's global.json error message on the selected SDK
AriusII Sep 23, 2026
c71e919
Stop governance workflow scripts on the first error
AriusII Sep 23, 2026
84768ff
Describe the dependency snapshot gap and the locked restore
AriusII Sep 23, 2026
caee9d1
Consume the exact CI package in the packaging fixture
AriusII Sep 23, 2026
d594f61
Check clean package consumers for workspace leakage
AriusII Sep 23, 2026
2be4169
Regenerate the bridge audit manifest from the committed blob
AriusII Sep 23, 2026
3d0596b
Add release tuple, SBOM export and checksum tooling
AriusII Sep 23, 2026
7168fa2
Publish releases draft-first with attestations and verification
AriusII Sep 23, 2026
67041b0
Gate stable releases on the qualification matrix
AriusII Sep 23, 2026
026ba2e
Document the 2.0 release and verification procedure
AriusII Sep 23, 2026
ea6820b
Check live plugin output closures
AriusII Sep 23, 2026
59b739b
Fix the stale workflow pending list after integrating S-CI-REL
AriusII Sep 23, 2026
dd5b810
Fix the Q40 matrix evidence after integrating S-CI-REL
AriusII Sep 23, 2026
9f98c17
Record the Wave 1 changes in the changelog
AriusII Sep 23, 2026
2242c12
Describe the Wave 1 CI, supply-chain and qualification rules
AriusII Sep 23, 2026
0cfd781
Align the CodeRabbit instructions with the new required checks
AriusII Sep 23, 2026
fc7ace0
Ask for qualification, API and release impact in pull requests
AriusII Sep 23, 2026
e3f3403
Point the README at the support profile and the documentation index
AriusII Sep 23, 2026
fc3afe3
Link the qualification pages from the plugin guides
AriusII Sep 23, 2026
1487aae
Re-flow a broken line in the address list example
AriusII Sep 23, 2026
ebae521
Describe the qualification tests in the Repository tests README
AriusII Sep 23, 2026
eda2696
Remove the zizmor cooldown exception now that Dependabot waits
AriusII Sep 23, 2026
12273b4
Ignore the out-of-solution formatting commit in git blame
AriusII Sep 23, 2026
fc05ed4
Stop calling the bridge source asset audited in the tests README
AriusII Sep 23, 2026
b47688c
Read the committed bridge hash from the audit manifest
AriusII Sep 23, 2026
156e700
Remove local qualification protocol and matrix documents
AriusII Sep 23, 2026
ecc9fbd
Remove obsolete configuration and script files
AriusII Sep 23, 2026
b2f1e18
Remove dangling script references from CI workflows
AriusII Sep 23, 2026
1a51248
Drop CheatEngine.SDK.slnx entries for deleted eng and docs files
AriusII Sep 23, 2026
8ae268c
Restore the protected Lua operation catalog beside its consumer
AriusII Sep 23, 2026
0a8d108
Delete tests for removed governance and release-tuple scripts
AriusII Sep 23, 2026
540a1b8
Adapt surviving tests to the inlined workflows and moved catalog
AriusII Sep 23, 2026
e4c39e3
Chain the caught exception in two process-timeout errors
AriusII Sep 23, 2026
183a13a
Update maintainer docs for the no-custom-scripting pivot
AriusII Sep 23, 2026
52f25f6
Remove the old path of the qualification-shape test move
AriusII Sep 23, 2026
d85cd8b
Regenerate lock files for the Meziantou.Analyzer 3.0.283 bump
AriusII Sep 23, 2026
8456f35
Remove dangling docs/ links from root README and ROADMAP
AriusII Sep 23, 2026
940fdda
Remove dangling Lua surface catalogue links from exemples READMEs
AriusII Sep 23, 2026
d6b7648
Remove dangling NativeAOT profile links from probe/harness READMEs
AriusII Sep 23, 2026
ce271fd
Delete stale PR policy check mentions from template and coderabbit
AriusII Sep 23, 2026
e1f99bc
Sync the AotProbe lock file with Meziantou.Analyzer 3.0.283
AriusII Sep 23, 2026
a216154
Start Lua status enums at Unknown instead of Success
AriusII Sep 23, 2026
220eb94
Add LuaOptional for explicit Lua argument omission
AriusII Sep 23, 2026
0c5a20f
Report the factual result count of generated Lua calls
AriusII Sep 23, 2026
7d21fd2
Generate optional arguments and optional or variadic results
AriusII Sep 23, 2026
96a5257
Require the ce77 contract and add optional Engine API grammar
AriusII Sep 23, 2026
5a0d0d2
Refuse floats at or above 2^53 in integer and address marshallers
AriusII Sep 23, 2026
8984dd6
Test Q20 to Q22 fidelity at binding and Engine level
AriusII Sep 23, 2026
edcd86f
Guard generator inventory, identity stability and AOT emission
AriusII Sep 23, 2026
26b2c79
Ban reflection-based type enumeration in shipping libraries
AriusII Sep 23, 2026
889a997
Document optional, variadic and marshalling contracts
AriusII Sep 23, 2026
56f65ee
Give instruction and process status enums an Unknown zero value
AriusII Sep 23, 2026
66a70a5
Map the CE x86 family with 64-bit targets to the x64 profile
AriusII Sep 23, 2026
0249bae
Observe target ISA, bitness and configured pointer size separately
AriusII Sep 23, 2026
3edce3b
Produce RuntimeInfo from read-only Cheat Engine runtime probes
AriusII Sep 23, 2026
c1e192d
Mark PointerSize.FromArchitecture obsolete as CESDK7001
AriusII Sep 23, 2026
9b82c03
Declare the local CE backend in qualified-target test fixtures
AriusII Sep 23, 2026
24bcf18
Refuse local incarnation evidence for CEServer and file targets
AriusII Sep 23, 2026
1f29f29
Record the assemble preference and range-check option in results
AriusII Sep 23, 2026
7aa07c4
Generate runtime capability probes from the ce77 runtime spec
AriusII Sep 23, 2026
e0f54d3
Document runtime facts, target backends and instruction profiles
AriusII Sep 23, 2026
3dd878a
Evidence Q30.c, Q30.d, Q31, Q32 and the SDK side of Q45 at C1 and C2
AriusII Sep 23, 2026
c770ecf
Flag PointerSize values built from the plugin process width
AriusII Sep 23, 2026
eeac547
Scan only code for obsolete and experimental diagnostic ids
AriusII Sep 23, 2026
f02851f
Report any selection that differs on re-check as TargetChanged
AriusII Sep 23, 2026
10992f8
Refuse integral floats for every integer runtime fact
AriusII Sep 23, 2026
591a77c
Name the generated CEServer probe like the backend enum
AriusII Sep 23, 2026
e6c458c
Narrow the README claim about bracketing PID reads
AriusII Sep 23, 2026
45ee749
Replace a tautological RuntimeInfo assertion with a real variant
AriusII Sep 23, 2026
adc2f82
Keep the backend contract inside the Engine sources and README
AriusII Sep 23, 2026
835037a
State and pin the integer policy of the generated runtime probes
AriusII Sep 23, 2026
765f67a
Find diagnostic ids in attribute lists and refuse non-literal ids
AriusII Sep 23, 2026
7e206b5
Correct two runtime-fact documentation remarks
AriusII Sep 23, 2026
9118bb9
Bind Engine resources to their runtime origin and report outcomes
AriusII Sep 23, 2026
1284acf
Document runtime-origin ownership and the Checkpoint D table
AriusII Sep 23, 2026
37634c4
Drop the dangling qualification-matrix link from the Engine README
AriusII Sep 23, 2026
ff1733e
Stop reading a no-call symbol release as a success
AriusII Sep 23, 2026
675871b
Remove an unreachable catch and clarify a stale-owner throw
AriusII Sep 23, 2026
29a12cc
Drop stale pre-renumbering PublicAPI entries after the rebase
AriusII Sep 23, 2026
92bf0e3
Remove the already-fixed SymbolRegistrationReleaseKind pending entry
AriusII Sep 23, 2026
76fcad2
Give the scan status enums an Unknown zero value
AriusII Sep 23, 2026
a283e77
Model zero AOB matches the way Cheat Engine 7.7 reports them
AriusII Sep 23, 2026
332b059
Destroy an AOB result list once when its owner cannot be published
AriusII Sep 23, 2026
193ac3e
Report target observations around a global AOB scan
AriusII Sep 23, 2026
70d6291
Add byte-array scan requests and AOB scan bounds
AriusII Sep 23, 2026
f11b5f1
Add deadline, cooperative termination and error text to scan sessions
AriusII Sep 23, 2026
cae217a
Stop a running scan before releasing its session
AriusII Sep 23, 2026
5864456
Add an exhaustive AOB scan bounded by a target range
AriusII Sep 23, 2026
902d697
Add an experimental first-found AOB scan
AriusII Sep 23, 2026
5e04fb0
Cover the remaining scan qualification battery
AriusII Sep 23, 2026
084938d
Document scan limits, costs and the pinned zero-match behavior
AriusII Sep 23, 2026
566e70b
Refuse disposed-session scan members and drop an unused using
AriusII Sep 23, 2026
861e872
Defer a scan-session release requested from inside its own CE wait
AriusII Sep 23, 2026
a9ce1c7
State what the bounded-scan zero and host-scan time contain
AriusII Sep 23, 2026
f60713b
Release a bounded scan's session when staging allocation fails
AriusII Sep 23, 2026
c46b508
Drop dead qualification-runner links and sharpen a doc remark
AriusII Sep 23, 2026
74d1576
Read API gate diagnostics without stumbling on comments or URLs
AriusII Sep 23, 2026
ec1a51e
Reflect over built assemblies for the API gate catalog
AriusII Sep 23, 2026
04afab1
Restore lot content against the current branch tip
AriusII Sep 23, 2026
c96086d
Drop the JSON Schema layer from the ABI and Lua-bridge document tests
AriusII Sep 23, 2026
8a0a066
Publish the NativeAOT plugin restrictions in the product READMEs
AriusII Sep 23, 2026
b705a20
Reconcile the NativeAOT harness and Repository.Tests READMEs
AriusII Sep 23, 2026
aab5cae
Add the NativeAOT loader harness test project to the solution
AriusII Sep 23, 2026
2d948dc
Format the reconciled files and fix a dotnet-format merge artifact
AriusII Sep 23, 2026
f1545c7
Fix two test regressions found by the targeted Repository.Tests run
AriusII Sep 23, 2026
eead140
Add the lock file for the NativeAOT loader harness tests project
AriusII Sep 23, 2026
752d368
Record the Wave 2 changes in the changelog
AriusII Sep 23, 2026
0e51173
Point plugin authors at the NativeAOT restriction from the README
AriusII Sep 23, 2026
6118ff5
Drop the dangling docs/catalog reference from the EngineApi README
AriusII Sep 23, 2026
8c43791
Mark plugin name ANSI encoding unqualified pending host validation
AriusII Sep 23, 2026
84540d2
Add opt-in bounded identification diagnostic at enable
AriusII Sep 23, 2026
53fb86c
Add tests for the load identification diagnostic
AriusII Sep 23, 2026
0ea6a96
Add the C2 native hostfxr host emulator for coexistence evidence
AriusII Sep 23, 2026
3d64aa4
Append epoch and Hosting type handle to the coexistence identity line
AriusII Sep 23, 2026
4720d4a
Consume the native host emulator from Hosting.Tests
AriusII Sep 23, 2026
01a474c
Add repository checks for the native host emulator build script
AriusII Sep 23, 2026
a606314
Refuse Lua on worker threads by default and detect external resets
AriusII Sep 23, 2026
dae406f
Stop claiming one Lua runtime per plugin without host evidence
AriusII Sep 23, 2026
7da5c58
Contain reentrant and throwing HostLog sinks during ABI callbacks
AriusII Sep 23, 2026
520e18f
Merge wip/s-host-core into wip/s-host (WI-1, WI-2, WI-3, WI-6)
AriusII Sep 23, 2026
77b0163
Merge wip/s-host-diag into wip/s-host (WI-4, WI-5)
AriusII Sep 23, 2026
f755dc9
Merge wip/s-host-emulator into wip/s-host (WI-7)
AriusII Sep 23, 2026
a31cbbc
Add the WI-8 exit tests for A04-01, A05-01 and A08-28
AriusII Sep 23, 2026
c6d74f3
Document the merged S-HOST test additions as README promises
AriusII Sep 23, 2026
f9455fd
Correct the emulator README's known-dependency facts and fix
AriusII Sep 23, 2026
ae101a7
Assert the eager-stamp baseline in the empty-IO memory test
AriusII Sep 23, 2026
6a2758d
Enable the EntryPoint generator on the coexistence fixture props
AriusII Sep 23, 2026
ab3e12e
Drop the coexistence plugins from the pending-entry-point list
AriusII Sep 23, 2026
04d8e4a
Wire the native host emulator job and document Wave 2 for 2.0.0
AriusII Sep 23, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
100 changes: 78 additions & 22 deletions .coderabbit.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ early_access: false

reviews:
# Assertive and advisory: CodeRabbit reviews thoroughly but never approves, requests changes or sets a required
# status. The only merge requirement is the CI / Gate check.
# status. The merge requirement is the CI / Gate check; there is no merge queue.
profile: assertive
request_changes_workflow: false
review_details: false
Expand Down Expand Up @@ -39,11 +39,12 @@ reviews:
mode: warning
requirements: >-
Pull requests are squash-merged and the title becomes the commit subject: a short imperative sentence such as
"Fix CI validation findings", at most 72 characters, no trailing period.
"Fix CI validation findings", at most 72 characters, no trailing period, no Conventional Commit or area prefix,
starting with an uppercase letter.
description:
mode: warning
issue_assessment:
mode: 'off' # issues are disabled on this repository
mode: 'off' # pull requests are not required to link an issue
docstrings:
mode: 'off' # CS1591 already fails the build for undocumented public APIs
custom_checks:
Expand All @@ -68,6 +69,23 @@ reviews:
path (conversion failure, callback exception, protected-call error) and that registry references and
callbacks are released. Fail when such code changes without those assertions, or when a raw Lua call that
can raise is added outside a protected boundary.
- name: Lua concurrency contract
mode: warning
instructions: >-
Applies only when the pull request changes libs/CheatEngine.SDK.Lua/Runtime/**; otherwise pass. Fail when
worker-thread Lua admission is widened, exposed or defaulted to on without staying behind
`[Experimental("CESDK5001")]`, when a comment or doc claims worker-thread admission is qualified before the
Q19 C3 and C4 receipts both pass, or when new code assumes the SDK serializes two plugins or two SDK copies
against each other (ADR-07: admission protects only this copy's attach/reset/detach transitions, never the
shared Lua heap). Otherwise pass.
- name: Native host emulator evidence
mode: warning
instructions: >-
Applies only when the pull request changes tests/native-host-emulator/** or
tests/CheatEngine.SDK.Hosting.Tests/Coexistence/**; otherwise pass. Fail when a description, comment or test
name presents the emulator's facts as live Cheat Engine host behavior or as a C4 (two-copy) qualification
receipt, rather than C2 hostfxr component-route evidence; or when an absolute path can reach the emitted
`--facts` output. Otherwise pass.
- name: Public API documentation and changelog
mode: warning
instructions: >-
Expand All @@ -88,12 +106,28 @@ reviews:
mode: warning
instructions: >-
Applies only to changes under .github/; otherwise pass. Fail when an action is referenced by tag or branch
instead of a full 40-character commit SHA with a version comment; pull_request_target is used;
actions/checkout omits persist-credentials: false; a permission is widened without a comment giving the
reason; a PowerShell step runs a native command (dotnet, xmake, git, gh, tar, actionlint) without checking
$LASTEXITCODE; SONAR_TOKEN or NUGET_USER can reach fork or Dependabot runs; a job added to ci.yml is missing
from the Gate's needs; or NuGet/login moves out of the release.yml publish job that uses environment nuget.
Otherwise pass.
instead of a full 40-character commit SHA with a version comment; pull_request_target or a merge_group
trigger is used; a job runs on a -latest label or on any label other than windows-2025 or ubuntu-24.04, or
has no timeout-minutes; actions/checkout omits persist-credentials: false; a permission is widened without a
comment giving the reason; a PowerShell step runs a native command (dotnet, xmake, git, gh, tar, actionlint)
without checking $LASTEXITCODE; a restore is not locked, or a job of ci.yml, sonar.yml, codeql.yml or
release.yml enables a package cache; SONAR_TOKEN or NUGET_USER can reach fork or Dependabot runs; a job added
to ci.yml is missing from the Gate's needs (WorkflowContractTests also fails; only the advisory client-canary
job may stay out); a zizmor finding is ignored in .github/zizmor.yml without a reason; or NuGet/login moves
out of the release.yml publish job that uses environment nuget. scorecard.yml is exempt from the pwsh
defaults and run-step rules, because Scorecard's publication verifier rejects them. The advisory workflows
(codeql, scorecard, zizmor-online, dependency-submission) stay outside the Gate. Otherwise pass.
- name: Public API and compatibility
mode: warning
instructions: >-
Applies when the pull request changes public or protected API under libs/ or src/, a PublicAPI.Shipped.txt
or PublicAPI.Unshipped.txt file, src/CheatEngine.SDK/CompatibilitySuppressions.xml, or a packages.lock.json
file; otherwise pass. Pass when every public API change is recorded in the owning library's
PublicAPI.Unshipped.txt (a changed or removed shipped declaration also gets a *REMOVED* line);
PublicAPI.Shipped.txt changes only in a release pull request that moves Unshipped into it;
CompatibilitySuppressions.xml changes only together with an intentional break that the description and the
CHANGELOG declare; and every packages.lock.json change comes from a CLI restore (never a hand edit)
together with the package, project or global.json change that caused it. Fail otherwise.
finishing_touches:
docstrings:
enabled: false
Expand Down Expand Up @@ -157,29 +191,51 @@ reviews:
- path: 'tests/**'
instructions: >-
Tests use xUnit v3 with Microsoft.Testing.Platform. CI runs the whole solution once in Debug and once in
Release with --fail-skips on, so a skipped test fails both. Distinguish fixture, package and NativeAOT probes
from actual live Cheat Engine host qualification.
Release with --fail-skips on, so a skipped test fails both. Debug excludes the packaging tests by the trait
Category=Packaging (never by Skip); Release runs them against the exact nupkg it packed
(CESDK_PACKAGED_UMBRELLA_NUPKG). A test that evidences a qualification scenario carries
[Trait("Qualification", "Qxx")] naming the C0-C4 level it reaches; a C1/C2 success is never presented as
host-qualified. Distinguish fixture, package and NativeAOT probes from actual live Cheat Engine host
qualification.
- path: 'CHANGELOG.md'
instructions: >-
Keep a Changelog 1.1.0. The release workflow publishes the body of the "## [X.Y.Z]" section (or [Unreleased]
for a prerelease) as the GitHub release notes, so keep version headings exact and link references at the end.
- path: '.github/**'
instructions: >-
pull-request-ci.yml, main-ci.yml and release.yml are thin callers of the reusable ci.yml (native, build-test
matrix Debug/Release, aot, sonar through sonar.yml, lint, gate) and must stay thin. Jobs exchange artifacts
instead of redoing work: lua-protection-bridge and classic-abi-fixture-facts from native; nuget-package,
coverage and test-results-<configuration> from build-test; release-notes from the release verify job. Do not
reintroduce per-project test matrices, a second test run of the same configuration, or rebuilds of what an
upstream job produced. NativeBridgePeAuditTests asserts the native job text. The Gate evaluates toJSON(needs)
and only sonar may be skipped. NuGet/login stays in release.yml with environment nuget (trusted publishing
binding). Require SHA-pinned actions, least privilege, persist-credentials: false and $LASTEXITCODE checks.
actionlint already runs in CI; do not ask for a duplicate CodeRabbit actionlint run. Never use
pull_request_target. Sonar secrets must stay unavailable to forks and Dependabot.
pull-request-ci.yml and main-ci.yml are thin callers of the reusable ci.yml (native, build-test matrix
Debug/Release, aot, sonar through sonar.yml, lint, format, dependency-review, lock-files, gate) and must stay
thin. Jobs exchange artifacts instead of redoing work: lua-protection-bridge and classic-abi-fixture-facts from
native; nuget-package, coverage and test-results-<configuration> from build-test.
The Release leg packs before it tests, and the packaging tests consume that exact nupkg. Do not reintroduce
per-project test matrices, a second test run of the same configuration, or rebuilds of what an upstream job
produced. NativeBridgePeAuditTests asserts the native job text, and WorkflowContractTests freezes job ids and
names, gate.needs, runners, pins, locked restores and the reserved artifact names. Every job runs on
windows-2025 or ubuntu-24.04 (never -latest) with a timeout, restores with --locked-mode, and no job of ci.yml,
sonar.yml, codeql.yml or release.yml uses a package cache. The Gate evaluates toJSON(needs): every job must
succeed, and sonar must match SONAR_EXPECTED (it runs exactly when expected and is skipped only for forks,
Dependabot, the dormant merge_group clause and release runs); no other job may be skipped. The required check
is CI / Gate. CodeQL, Scorecard, zizmor-online and dependency-submission are advisory and stay out of the
Gate; scorecard.yml keeps no defaults, env or run steps. release.yml is draft-first (verify, ci, attest,
draft-release, publish, verify-publication, finalize-release); publication jobs run only for v* tags of this
repository, never upload to a published release, and keep NuGet/login in the publish job with environment
nuget (trusted publishing binding). Require SHA-pinned actions, least privilege, persist-credentials: false,
user-controlled values only through env, and $LASTEXITCODE checks. actionlint and zizmor already run in the
lint job; do not ask for a duplicate CodeRabbit run. Never use pull_request_target. Sonar secrets must stay
unavailable to forks and Dependabot. No custom PowerShell/Python/JSON governance or evidence tooling under
eng/: a genuine build necessity currently wrapped in a bespoke script gets inlined as direct run: lines using
standard actions and CLI calls instead.
- path: '**/*.md'
instructions: >-
Never restore or link the retired documentations/ tree. Narrative documentation (qualification protocol,
catalogues, migration guides) lives outside both repositories, under the maintainer's local docs/ tree, not
in a repository docs/ folder: flag a pull request that recreates one. Relative links keep the exact case of
the target; READMEs packed into the NuGet package use absolute links only.
tools:
# CodeRabbit is used as the GitHub App; pipeline failures are surfaced through its GitHub Checks integration.
github-checks:
enabled: true
# The ci.yml lint job is the deterministic actionlint owner.
# actionlint and zizmor run in the lint job of ci.yml, the deterministic owner of both.
actionlint:
enabled: false

Expand Down
13 changes: 13 additions & 0 deletions .config/dotnet-tools.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
{
"version": 1,
"isRoot": true,
"tools": {
"dotnet-coverage": {
"version": "18.11.2",
"commands": [
"dotnet-coverage"
],
"rollForward": true
}
}
}
32 changes: 18 additions & 14 deletions .editorconfig
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,8 @@ indent_size = 4
tab_width = 4
max_line_length = 120
trim_trailing_whitespace = true
# Matches .gitattributes (eol=crlf): dotnet format and the IDE0055 build check agree on CRLF.
end_of_line = crlf

[*.{csproj,props,targets,slnx,config,json,yml,yaml}]
# YAML cannot use tabs for indentation. Keep project and configuration files
Expand Down Expand Up @@ -75,24 +77,22 @@ csharp_style_prefer_top_level_statements = false
# blockers because Directory.Build.props treats warnings as errors.
dotnet_diagnostic.IDE0079.severity = error

# Migration rules: surface the historical backlog in every Roslyn-aware editor
# and participate in code cleanup without breaking the currently dirty tree.
# Promote these to warning/error in a dedicated cleanup change once the existing
# source has been reformatted and explicit types have been introduced.
# Style rules enforced since the repository-wide reformat of the audit remediation branch
# (see .git-blame-ignore-revs). EnforceCodeStyleInBuild plus TreatWarningsAsErrors turns them into build errors,
# and CI also runs `dotnet format --verify-no-changes`.
dotnet_diagnostic.IDE0007.severity = none
dotnet_diagnostic.IDE0008.severity = suggestion
dotnet_diagnostic.IDE0011.severity = suggestion
dotnet_diagnostic.IDE0008.severity = warning
dotnet_diagnostic.IDE0011.severity = warning
dotnet_diagnostic.IDE0033.severity = suggestion
dotnet_diagnostic.IDE0040.severity = suggestion
dotnet_diagnostic.IDE0044.severity = suggestion
# The formatter still follows the tab contract above. Do not flood every open
# legacy file with a formatting diagnostic before the dedicated reformat pass.
dotnet_diagnostic.IDE0055.severity = none
dotnet_diagnostic.IDE0040.severity = warning
dotnet_diagnostic.IDE0044.severity = warning
dotnet_diagnostic.IDE0055.severity = warning
dotnet_diagnostic.IDE0005.severity = suggestion
dotnet_diagnostic.IDE0065.severity = suggestion
dotnet_diagnostic.IDE0090.severity = suggestion
dotnet_diagnostic.IDE0065.severity = warning
dotnet_diagnostic.IDE0090.severity = warning
dotnet_diagnostic.IDE0160.severity = none
dotnet_diagnostic.IDE0161.severity = suggestion
dotnet_diagnostic.IDE0161.severity = warning
# Naming fixes rename symbols, which dotnet format cannot apply safely; keep them as editor guidance.
dotnet_diagnostic.IDE1006.severity = suggestion

# Rider derives its own "var or explicit type" inspections from the shared
Expand Down Expand Up @@ -148,3 +148,7 @@ dotnet_diagnostic.IDE0005.severity = error

[src/**.cs]
dotnet_diagnostic.IDE0005.severity = error

# The native bridge embeds the SHA-256 of these two files; .gitattributes pins them to LF.
[native/cheatengine-sdk-lua-bridge/{cheatengine_sdk_lua_bridge.c,xmake.lua}]
end_of_line = lf
5 changes: 5 additions & 0 deletions .git-blame-ignore-revs
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
# Commits that only reformat code. Enable locally with: git config blame.ignoreRevsFile .git-blame-ignore-revs
# Apply repository formatting
0a03dac0cae53d399e89dfb1494ac80843a3ab9a
# Format the projects that live outside the solution (AotProbe, LiveProbe)
fc6016532f5f1d963d1cf267a1750bbbfa64cc49
16 changes: 16 additions & 0 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
# Informational only: the "Protect main" ruleset does not require a code-owner review (single active maintainer; a
# required review would block every maintainer and Dependabot pull request). GitHub still requests a review from the
# owners below. Owners must have write access; confirm co-owners with the maintainer before adding them.
# Syntax: https://docs.github.com/en/repositories/managing-your-repositorys-settings-and-features/customizing-your-repository/about-code-owners
# The last matching pattern wins, so the catch-all comes first.
* @AriusII

# Native authority: the protection bridge, the ABI layouts and the build assets consumers import.
/native/ @AriusII
/libs/CheatEngine.SDK.Abi/ @AriusII
/src/CheatEngine.SDK/build/ @AriusII

# Build, release and governance: workflows, the PR policy code and repository settings.
/.github/ @AriusII
/eng/ @AriusII
/SECURITY.md @AriusII
62 changes: 62 additions & 0 deletions .github/ISSUE_TEMPLATE/bug_report.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,62 @@
# Schema: https://docs.github.com/en/communities/using-templates-to-encourage-useful-issues-and-pull-requests/syntax-for-githubs-form-schema
name: Bug report
description: An SDK API, analyzer, generator or build asset behaves differently from its documentation.
title: "[Bug] "
labels: [ bug ]
body:
- type: markdown
attributes:
value: |
Use this form for a defect in the SDK itself. When a plugin does not load, or works with one Cheat Engine,
runtime or package combination and not another, use the **Compatibility report** form instead: it records the
exact tuple the problem depends on. Security problems go to private reporting (see SECURITY.md).

- type: input
id: sdk-version
attributes:
label: CheatEngine.SDK version
description: The `resolved` version of `CheatEngine.SDK` in the plugin's `packages.lock.json`, or the commit when you build from source.
placeholder: "1.0.0"
validations:
required: true

- type: input
id: ce-version
attributes:
label: Cheat Engine build
description: The exact file version, or `not involved` for an analyzer, generator or build problem.
placeholder: "7.7.0.10621"
validations:
required: true

- type: textarea
id: steps
attributes:
label: Steps to reproduce
description: A minimal plugin or code snippet and the actions that trigger the problem.
validations:
required: true

- type: textarea
id: expected
attributes:
label: Expected result
validations:
required: true

- type: textarea
id: actual
attributes:
label: Observed result
description: What happened instead, with the exact error text or diagnostic id.
validations:
required: true

- type: textarea
id: logs
attributes:
label: Logs (optional)
description: Relevant, redacted build output or log lines. Remove user names and private paths first.
render: text
validations:
required: false
Loading
Loading