Skip to content

Fix deployment audit findings and CodeQL build coverage - #112

Merged
ostomachion merged 1 commit into
mainfrom
codex/deployment-audit-fixes
Sep 22, 2026
Merged

ostomachion merged 1 commit into
mainfrom
codex/deployment-audit-fixes

Conversation

@ostomachion

@ostomachion ostomachion commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Start from main 67bb72e, including the latest Dependabot merges.
  • Trace a real Release build for C# CodeQL instead of the synthetic no-build Razor compilation; preserve immutable action pins and disable dependency/checkout credential persistence.
  • Keep the current NuGet-backed Aspire dependency mode explicit and acknowledge only ASPIRE010, which also caused the formatter's generic workspace warning.
  • Correct Dependabot's API-image grouping to match registry-free dependency names and add a regression check; document registry cooldown limitations.
  • Recover a stopped shared edge even when candidate files are unchanged, while leaving a running edge untouched. Add regression coverage and host verification/recovery guidance.
  • Record successful staging/production application evidence without claiming unverified host state or SSH trust provenance.

Validation

  • dotnet restore opengamebuilder.slnx
  • dotnet format opengamebuilder.slnx --verify-no-changes --no-restore --verbosity diagnostic (clean, no workspace warning)
  • dotnet build opengamebuilder.slnx --configuration Release --no-restore -m:1 (0 warnings, 0 errors)
  • dotnet test --solution opengamebuilder.slnx --configuration Release --no-build (72 passed)
  • Non-incremental Release build with CodeQL's injected compiler flags passed and emitted all five Razor generated sources.
  • Isolated release-script, application deployment, edge deployment (9 cases), and supply-chain suites passed.
  • Dependabot grouping and stopped-edge regressions failed before their fixes and pass afterward.
  • git diff --check passed; independent non-CodeQL diff review found no actionable issues.

Remaining acceptance and operator work

  • Hosted C# CodeQL extraction, query analysis, and upload are now verified; see the results below.
  • GitHub-managed Code Quality is a separate generated workflow without the same manual build-mode setting. Keep enabled; its synthetic compiler warning may still require upstream support.
  • After merge, an administrator should verify the native host Caddy service is disabled/inactive, inspect runtime logs and the running image pin, and apply CD Shared Edge from main if needed. Application deploys do not update the shared proxy.
  • Docker runtime-token diagnostic and artifact-download deprecation warnings are upstream; no broad warning suppression added.
  • No deployment, production release, environment setting change, or server credential access was performed.

AI assistance was used to implement, test, and review these changes.

Hosted verification

  • CI 35676867055: passed all 72 tests, every isolated script suite, the actual Docker build, and the non-root/read-only application-directory/liveness probe. Build reports 0 warnings and 0 errors; formatter workspace warning is absent.
  • CodeQL Advanced 35676867021: Actions and C# passed. Real Release build, database/query analysis, and result upload completed. The former synthetic compiler exit-code error is absent.
  • GitHub-managed Code Quality 35676865464: green, but retains synthetic no-build Razor diagnostics and two unresolved layout types. A misleading intermediate feed warning is followed by successful restores and zero unresolved assembly references. Keep this separately managed scan enabled; no package-source change is justified.
  • All PR checks passed at head 2dd24f1. Informational runner notice: ubuntu-latest starts migrating to Ubuntu 26 on October 19, 2026.
  • Working tree is clean. No merge, deployment, or release was performed.

@ostomachion
ostomachion merged commit 84e58ab into main Sep 22, 2026
6 checks passed
@ostomachion
ostomachion deleted the codex/deployment-audit-fixes branch September 22, 2026 01:50
@github-project-automation github-project-automation Bot moved this from Triage to Done in OpenGameBuilder Roadmap Sep 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Development

Successfully merging this pull request may close these issues.

1 participant