Skip to content

Add support for PackageGuard and use it in the pipeline - #659

Open
dennisdoomen wants to merge 2 commits into
developfrom
claude/packageguard-generated-support-e39906
Open

Add support for PackageGuard and use it in the pipeline#659
dennisdoomen wants to merge 2 commits into
developfrom
claude/packageguard-generated-support-e39906

Conversation

@dennisdoomen

@dennisdoomen dennisdoomen commented Aug 25, 2026

Copy link
Copy Markdown
Collaborator

Adds a Fallout CLI tool wrapper for PackageGuard's analyze command, based on AnalyzeCommandSettings.cs, and wires it into the build pipeline as a compliance gate plus SBOM/risk-reporting.

Tool wrapper

  • src/Fallout.Common/Tools/PackageGuard/PackageGuard.json — spec covering all 18 analyze settings, plus NpmPackageManager and SbomFormat enumerations for the properties restricted to a fixed set of values.
  • PackageGuard.Generated.cs — regenerated via ./build.ps1 GenerateTools.
  • Added a row to the supported-tools table in docs/website/03-common/08-cli-tools.md.
  • Added TestPackageGuard to tests/Fallout.Common.Specs/SettingsSpecs.cs.

Build pipeline

  • New PackageGuard target (build/Build.PackageGuard.cs) runs the policy-violation check on every PR (added to build.yml's required gate, alongside VerifyGeneratedTools/Test/Pack) — a license/package-policy violation now blocks the PR gate like any other check.
  • The SBOM (CycloneDX) and HTML + SARIF risk report are only generated on main, develop, release/*, or support/* — via GitRepository.IsOn*Branch() (including a new IsOnSupportBranch() extension), or, for the tag-triggered release workflow where HEAD is detached, because that workflow's own validate-ref job already proved the tag is reachable from a production branch.
  • New security-scan workflow (generated from a third [GitHubActions] attribute) runs on every push to those branches and uploads the SARIF report to GitHub code scanning via github/codeql-action/upload-sarif.
  • publish-packages-release.yml now runs PackageGuard alongside Test+Pack and attaches both the SBOM and the HTML risk report to the GitHub Release as assets.
  • Added .packageguard/config.json — an allowlist covering the permissive license family this repo's actual dependencies use (MIT, Apache-2.0, BSD-2/3-Clause, ISC, 0BSD, MS-PL), plus an explicit package-name allowance for FluentAssertions (its pinned 8.10.0 reports no SPDX license expression at all — a licenseFile plus a note that commercial use requires a paid Xceed license — so no license-based match would cover it; mirrors the same allowance PackageGuard's own repo uses on itself). Without a config file, PackageGuard's NuGet analysis throws on every run instead of defaulting permissive, which would have broken every PR the moment this became a required check.

Purely additive — no breaking changes.

🤖 Generated with Claude Code

@dennisdoomen dennisdoomen added enhancement New feature or request target/vCurrent Targets the current version labels Aug 25, 2026
@dennisdoomen
dennisdoomen force-pushed the claude/packageguard-generated-support-e39906 branch from d0c4f43 to f3da768 Compare August 25, 2026 19:16
@dennisdoomen

Copy link
Copy Markdown
Collaborator Author

@ChrisonSimtian what do you think about this PR?

@ChrisonSimtian

Copy link
Copy Markdown
Collaborator

@ChrisonSimtian what do you think about this PR?

I love the idea of having this baked in, it adds real value to the CI

@dennisdoomen
dennisdoomen force-pushed the claude/packageguard-generated-support-e39906 branch 2 times, most recently from e5d1a2a to 331023a Compare August 28, 2026 07:09
dennisdoomen added a commit that referenced this pull request Aug 28, 2026
Its NuGet metadata carries no license expression or URL, same gap as
FluentAssertions above it — PackageGuard can't auto-detect either
despite both being MIT. See #659.
Explicitly allows NetArchTest.Rules alongside FluentAssertions in
.packageguard/config.json — both are MIT-licensed but publish no
license expression or URL for PackageGuard to auto-detect.
Fixes a race with PromptConfirmationGlyphSpecs: both mutate the shared
static ConsoleUtility.ConsoleWrapper/IsInterrupted, but only the glyph
specs opted into ProcessGlobalStateCollection. xUnit runs different
collections in parallel, so the two classes intermittently stomped on
each other's console wrapper, surfacing as a FakeConsole.LastLine
'Sequence contains no matching element' failure in CI.
@dennisdoomen
dennisdoomen force-pushed the claude/packageguard-generated-support-e39906 branch from c926a33 to 2d4db33 Compare August 28, 2026 09:04
@dennisdoomen
dennisdoomen marked this pull request as ready for review August 28, 2026 09:12
@dennisdoomen
dennisdoomen requested a review from a team as a code owner August 28, 2026 09:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request target/vCurrent Targets the current version

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants