Skip to content

fix(hidi): separate v2 versions and route releases by component tag - #898

Merged
Gavin Barron (gavinbarron) merged 4 commits into
support/v2from
gavinbarron-hidi-v2-automated-versioning
Oct 9, 2026
Merged

Gavin Barron (gavinbarron) merged 4 commits into
support/v2from
gavinbarron-hidi-v2-automated-versioning

Conversation

@gavinbarron

@gavinbarron Gavin Barron (gavinbarron) commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Implements the user's standard multi-component versioning pattern from a65052d57fa5e623c765024fb05a0384691a9168 and the follow-up request: “The ADO pipeline that handles releases should be updated so that it only releases the component belonging to the triggering tag.”

  • Use the existing stock Release Please action with one config and one manifest for root OData (.) and Hidi (src/Microsoft.OpenApi.Hidi). Preserve the existing bootstrap, action/token pins, independent baselines OData 2.2.1 / Hidi 2.12.2, project XML updaters, changelogs and tag conventions.
  • Set the single supported separate-pull-requests: true option to preserve OData's existing componentless tag lifecycle; the stock engine otherwise fails to produce an OData candidate for a componentless root-only combined PR.
  • Remove the superseded custom runner, npm tooling, test/coverage job, label/checkpoint machinery, and duplicate Hidi config/manifest/job. Document standard source-directory boundaries honestly; root distribution/helper files remain root-owned.
  • Route the registered OData Azure pipeline (.azure-pipelines/ci-build.yml) only to v2. tags* and the dedicated Hidi pipeline (.azure-pipelines/hidi-release.yml) only to hidi-v2. tags*. Validate exact project/tag versions before staging artifacts; reject malformed, wrong-component, other-major, or mismatched manually selected tags.
  • Correct the OData DotNetCoreCLI@2 pack inputs: the old projects/arguments inputs are ignored for command: pack, defaulting to all projects. Use supported packagesToPack, configuration/output, no-build, symbols/source and format inputs so only OData is packaged and signed binaries are not rebuilt.
  • Release only the exact tag-derived package and verified symbols/artifacts. OData's NuGet/GitHub steps consume its validated exact file path; GitHub attachment runs only after successful validation. Hidi retains exact NuGet selectors and additionally verifies its executable/ZIP and Docker-context version.

Validation

All tooling and fixtures are session-only; no new test framework or workflow is committed.

  • Nine stock release-please 17.3.0 scenarios verify actual generated XML/changelog/shared-manifest output and pure merged-release candidates: Hidi fixes/features yield hidi-v2.12.3 / hidi-v2.13.0 with OData unchanged; OData fixes/features yield v2.2.2 / v2.3.0 with Hidi unchanged; mixed changes remain independent. Hidi-test/infrastructure-only and root Docker/helper boundaries are verified.
  • 89 actual YAML PowerShell guard/matrix cases cover OData/Hidi tags, branch/PR refs, unknown/malformed/case-variant/other-major tags, project-version mismatch, migration floors, exact and nested package selection, missing/wrong/duplicate/foreign component packages, symbols, executable/ZIP and container context. The existing hard-false Hidi flag prevents its release stage; no tag can select both components.
  • The official task schema/pack implementation confirms the supported inputs. An authorized read of existing ADO task 2.281.0 logs independently confirms the old pack step actually built Hidi, OData and GUI packages without the intended no-build/symbol/source flags.
  • Actual local no-build OData packing produces only Microsoft.OpenApi.OData.2.2.1.nupkg and its .snupkg. Nuspec ID/version match; the DLL SHA-256 is identical before/after packing. Both exact OData release guards accept these real package files. No ESRP/production publication was invoked.
  • YAML parses, the standard action workflow passes actionlint, and protected pipeline settings were compared directly against the prior accepted implementation.

Safety

Hidi publishing remains false. Protected environments, signing Yuriy Semchyshyn (@5), ESRP akari (@14), service connections, resource permissions, private-feed/BuildKit-secret handling, public-only Docker context and migration floors are unchanged. Ordinary branch/PR validation is retained; release stages remain tag-only. No actual tags/releases or publishing runs were created or queued, and no permissions were granted.

Both project baselines remain unchanged. SonarCloud/CI-CD are unchanged; no custom versioning runtime remains. Canonical imported ancestry is preserved through normal additional commits, not history rewriting. No auto-merge is configured; parent coordinates v2-first landing and the separate main counterpart.

Use the existing pinned release-please engine with exact component path exclusions and an isolated, tag-free Hidi version PR lifecycle. Preserve OData releases, baseline versions, and protected publishing gates; verify real generated plans, repeated cycles, and measured runner coverage.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 2dc4344a-fac5-4e6e-89f8-eb2c9467edd4
@gavinbarron
Gavin Barron (gavinbarron) requested a review from a team as a code owner October 9, 2026 18:33
Count open version PRs independently of seeded merged checkpoints so the full release-please suite continues to pass after the manifest advances. Verified all 80 cases against both the current and a generated future Hidi baseline.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 2dc4344a-fac5-4e6e-89f8-eb2c9467edd4
Comment thread .github/release-please/package.json Outdated
Follow the user-provided release-please configuration pattern with one shared config and manifest, independent component versions, and the existing stock action. Remove custom runner, npm tooling, test/coverage machinery, labels and duplicate Hidi scaffolding. Use the supported separate-pull-requests option to preserve componentless OData releases; keep package baselines and protected production publishers unchanged.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 2dc4344a-fac5-4e6e-89f8-eb2c9467edd4
@gavinbarron Gavin Barron (gavinbarron) changed the title fix(hidi): automate independent v2 version PRs fix(hidi): use standard v2 multi-component release configuration Oct 9, 2026
Release only OData for v2 tags and Hidi for hidi-v2 tags. Validate exact project/tag versions before artifact staging, select exact component packages and GitHub assets, and stop publishing after guard failures. Use supported DotNetCoreCLI pack inputs so the OData job does not default to packing Hidi and GUI projects or rebuilding signed binaries. Preserve existing protected environments, signing connections, Hidi publishing-off flag, private-feed behavior and migration floors.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 2dc4344a-fac5-4e6e-89f8-eb2c9467edd4
@gavinbarron Gavin Barron (gavinbarron) changed the title fix(hidi): use standard v2 multi-component release configuration fix(hidi): separate v2 versions and route releases by component tag Oct 9, 2026
@sonarqubecloud

sonarqubecloud Bot commented Oct 9, 2026

Copy link
Copy Markdown

@gavinbarron
Gavin Barron (gavinbarron) merged commit 7ab04f2 into support/v2 Oct 9, 2026
44 checks passed
@gavinbarron
Gavin Barron (gavinbarron) deleted the gavinbarron-hidi-v2-automated-versioning branch October 9, 2026 22:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants