Skip to content

Limit NuGet lockfiles to shipped applications - #119

Merged
ostomachion merged 1 commit into
codex/foundation-section-15-cifrom
codex/shipped-app-dependency-locks
Sep 22, 2026
Merged

ostomachion merged 1 commit into
codex/foundation-section-15-cifrom
codex/shipped-app-dependency-locks

Conversation

@ostomachion

@ostomachion ostomachion commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Dependabot PR #115 updated centrally managed OpenTelemetry versions but left the API test and platform-specific AppHost lockfiles stale, causing NU1004 before build. Keep committed NuGet locks for the shipped API and Web Client, and restore tests and the local-only AppHost normally. The solution still builds and tests all projects, and production restore/packaging still reject missing or stale locks.

Remove the four development lockfiles and their opt-ins. Update development, testing, and foundation guidance to describe the narrower guarantee and the simpler update procedure. Test and AppHost transitive graphs are no longer frozen; no bot write-back service is introduced.

Testing

  • pwsh ./scripts/check.ps1 full -Serial passed: zero-warning Release build, all 72 tests, content and CI policy regressions, frontend packaging/portability, smoke package checks, and all five shell suites.
  • The exact failing PR deps: Bump the nuget-minor-and-patch group with 2 updates #115 merge snapshot with this policy passed quick -Serial, including all 72 tests, with its OpenTelemetry 1.19.1 update.
  • Windows and Linux-selected dependency restores passed locally; the latter is not execution on a Linux host.
  • Missing API/Web locks were rejected without regeneration; a stale API graph failed with NU1004. Development locks were not regenerated. Both production lockfiles are unchanged.
  • Hosted CI run 35749500632 passed at b072449: Windows solution, Linux full validation, API container build/runtime checks, and build-test.

Notes for reviewers

This PR is deliberately stacked on #117 (codex/foundation-section-15-ci) following coordination with that ongoing task. Merge #117 first, then retarget this PR to main before merging; this PR's diff contains only the lock-policy change. The OpenTelemetry version bump stays in #115, which can pick up this policy after it reaches main.

AI-assisted implementation and documentation were reviewed and validated with the checks above. No local orchestration, credential changes, or deployments were performed.

@ostomachion
ostomachion marked this pull request as ready for review September 22, 2026 15:49
@ostomachion
ostomachion merged commit 8bdc90e into codex/foundation-section-15-ci Sep 22, 2026
5 checks passed
@ostomachion
ostomachion deleted the codex/shipped-app-dependency-locks branch September 22, 2026 15:49
@github-project-automation github-project-automation Bot moved this from Triage to Done in OpenGameBuilder Roadmap Sep 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Development

Successfully merging this pull request may close these issues.

1 participant