Repository navigation
Make the SDK pin job actually pin SDKs - #25
Merged
matt-edmondson merged 1 commit intoSep 16, 2026
Merged
Conversation
`update-sdks.yml` has been a silent no-op in every repository for as long as the feed has carried a prerelease. Each defect below was confirmed against the live NuGet feed rather than read off the source: - `[System.Version]::Parse` throws on `2.28.1-pre.1`, and the `catch` reported "may not be published to NuGet.org" and returned null, which the caller read as "no update available". Every lookup, every week, for every package. - `-like "ktsu.Sdk.*"` is False for `ktsu.Sdk`, and the csproj pattern required a suffix too, so the package nearly every repository pins was invisible. VST pins only that one, reported "No ktsu SDKs found", and sits on 2.8.0. - One version was recorded per package, first seen wins, and the package was skipped when that one was already current. A dependency bump that updates some entries and not others therefore left the rest behind permanently. - The `[\d\.]+` replacement read `2.0.0` out of `2.0.0-pre.1` and rewrote only that part, producing a version that had never been published. - `[bool]"false"` is `$true`, so `force_update` never forced anything. - `git push origin main` hardcoded a branch name. The replacement makes the reference the unit of work rather than the package, so a repository whose global.json and project files disagree is repaired even when no newer version exists. That is the property worth having: Dependabot already chases versions, but nothing guaranteed a repository ended up on one of them, and a build resolving two versions of the same SDK is not reproducible. The logic moves to scripts/update-sdks.ps1 so it can be run and tested outside Actions, which is the other half of why this went unnoticed for so long. Its tests are the defects above, each as a case. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014RABe2NufFc9hwm94iB3Rf
matt-edmondson
deleted the
claude/dependabot-ci-workflow-rollout-fbrhdn
branch
October 6, 2026 00:03
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Replaces the per-repository
update-sdks.ymlwith a shared reusable workflow and a tested script, and changes what the job is for: converging everyktsu.Sdk*reference in a repository on one version, rather than chasing the newest one.The job has been a no-op in every repository
Not a suspicion — each of these was reproduced against the live NuGet feed with PowerShell 7.5 before writing a line of the replacement:
[System.Version]::Parseon every published version2.28.1-pre.1(The input string '1-pre' was not in a correct format). Thecatchreported "Package may not be published to NuGet.org" and returned$null, which the caller read as "no update available". Every lookup, every week, for every package.-like "ktsu.Sdk.*", and aktsu\.Sdk\.\w+csproj pattern"ktsu.Sdk" -like "ktsu.Sdk.*"isFalse. Both miss the barektsu.Sdk, the package nearly every repository pins.VSTpins only that one, so the job reported "No ktsu SDKs found" and exited 0 — which is why it is on2.8.0.[\d\.]+replacement pattern2.0.0out of2.0.0-pre.1and rewrote only that part, producing a version that was never published.-not $env:FORCE_UPDATE[bool]"false"is$true, so the input never forced anything.git push origin mainConvertTo-Json -Depth 10round-tripLatest released
ktsu.Sdkis2.29.0. Four repositories sit on2.25.0, one on2.26.1, one on2.27.0,VSTon2.8.0. That spread is what a weekly green no-op adds up to.What replaces it
The unit of work is the reference, not the package. A repository whose
global.jsonand project files disagree is repaired even when no newer version exists. That is the property actually worth having here: Dependabot already chases versions and itsktsugroup raises them together, but nothing guaranteed a repository ended up on one of them, and a build resolving two versions of the same SDK is not reproducible.Beyond that: semantic version comparison, so
2.9.0sorts below2.28.1; prereleases are never a target but a reference already ahead of the latest release becomes the target rather than being rolled backwards; edits are textual and scoped to the version after the package name, so key order, formatting, unrelated entries and the trailing newline survive, and a prerelease pin is replaced whole.A lookup that fails now fails the run. Conflating "could not resolve" with "already up to date" is the specific thing that hid this for 35 runs.
Why a script rather than more YAML
250 lines of PowerShell embedded in a workflow can only be tested by merging it and waiting a week, which is the other half of why this went unnoticed.
scripts/update-sdks.ps1runs anywhere, andscripts/tests/update-sdks.tests.ps1is the defect list above turned into cases, so the file doubles as the record of what was wrong.The workflow fetches the script from this repository at
releaserather than checking it out, so it never lands in the workspace that the script scans andgit statusinspects.Verification
scripts/tests/update-sdks.tests.ps1— 7/7 pass on pwsh 7.5.4.BlastMerge'sglobal.json(9 entries at2.25.0) converges to2.29.0withMSTest.Sdk, key order and formatting untouched;VST's (barektsu.Sdkat2.8.0, the case that previously found nothing) converges too. The old code produced no change in either.2.29.0and one at2.25.0, the shape a partial group bump leaves — converges. The old code skipped the package entirely.[System.Management.Automation.SemanticVersion]parses all 172 publishedktsu.Sdkversions, orders2.9.0 < 2.28.1and2.28.1-pre.1 < 2.28.1.actionlintclean on the shared workflow and on the caller template; the template is byte-identical to the one in the docs, checked programmatically.markdownlintclean ondocs/sdk-pinning.mdanddocs/shared-ci.md;CLAUDE.mdstill reports its same 12 pre-existing findings.Not in this PR
Rolling the caller out to the 37 repositories that have an
update-sdks.yml, and adding it to the ones that should. That wave goes with theci.ymlfan-out.🤖 Generated with Claude Code
https://claude.ai/code/session_014RABe2NufFc9hwm94iB3Rf
Generated by Claude Code