From fe7ef5be2c6905982f0d5d341e1e44d046239c72 Mon Sep 17 00:00:00 2001 From: Claudio Mendes Date: Sat, 10 Oct 2026 12:06:26 +0200 Subject: [PATCH] Align repository validation and governance Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --- .editorconfig | 14 ++++ .github/CODEOWNERS | 9 +++ .github/ISSUE_TEMPLATE/bug_report.yml | 32 +++++++++ .../ISSUE_TEMPLATE/compatibility_report.yml | 39 +++++++++++ .github/ISSUE_TEMPLATE/config.yml | 5 ++ .github/ISSUE_TEMPLATE/feature_request.yml | 27 ++++++++ .github/dependabot.yml | 6 ++ .github/github-app.yml | 3 + .github/pull_request_template.md | 12 ++++ .github/workflows/validate.yml | 13 ++-- .vscode/extensions.json | 5 ++ .vscode/tasks.json | 65 +++++++++++++++++++ 12 files changed, 223 insertions(+), 7 deletions(-) create mode 100644 .editorconfig create mode 100644 .github/CODEOWNERS create mode 100644 .github/ISSUE_TEMPLATE/bug_report.yml create mode 100644 .github/ISSUE_TEMPLATE/compatibility_report.yml create mode 100644 .github/ISSUE_TEMPLATE/config.yml create mode 100644 .github/ISSUE_TEMPLATE/feature_request.yml create mode 100644 .github/dependabot.yml create mode 100644 .github/github-app.yml create mode 100644 .github/pull_request_template.md create mode 100644 .vscode/extensions.json create mode 100644 .vscode/tasks.json diff --git a/.editorconfig b/.editorconfig new file mode 100644 index 0000000..e537b81 --- /dev/null +++ b/.editorconfig @@ -0,0 +1,14 @@ +root = true + +[*] +charset = utf-8 +end_of_line = lf +insert_final_newline = true +indent_style = space +indent_size = 4 + +[*.ps1] +end_of_line = crlf + +[*.{yml,yaml,json}] +indent_size = 2 diff --git a/.github/CODEOWNERS b/.github/CODEOWNERS new file mode 100644 index 0000000..82a1696 --- /dev/null +++ b/.github/CODEOWNERS @@ -0,0 +1,9 @@ +* @vartaxe +/.github/ @vartaxe +/Content/ @vartaxe +/Data/ @vartaxe +/Driver Automation Tool/ @vartaxe +/HotFix/ @vartaxe +/LICENSES/ @vartaxe +/Tests/ @vartaxe +/SECURITY.md @vartaxe diff --git a/.github/ISSUE_TEMPLATE/bug_report.yml b/.github/ISSUE_TEMPLATE/bug_report.yml new file mode 100644 index 0000000..304efa3 --- /dev/null +++ b/.github/ISSUE_TEMPLATE/bug_report.yml @@ -0,0 +1,32 @@ +name: Bug report +description: Report a reproducible issue with the Driver Automation Tool +title: "[Bug]: " +labels: + - bug +body: + - type: textarea + id: summary + attributes: + label: Summary + description: What happened? Do not disclose credentials or internal identifiers. For security issues, use private vulnerability reporting from the Security tab; contact vartaxe@outlook.com privately if unavailable. + validations: + required: true + - type: textarea + id: environment + attributes: + label: Environment + description: Driver Automation Tool version, Windows version, Windows PowerShell version, ConfigMgr or Intune context, and whether the issue occurred in full Windows or WinPE. Sanitize identifiers. + validations: + required: true + - type: textarea + id: reproduction + attributes: + label: Reproduction and expected behavior + description: Describe minimal reproduction steps, expected and actual results, and the relevant process or exit code. Include only non-sensitive values and names. + validations: + required: true + - type: textarea + id: logs + attributes: + label: Sanitized logs + description: Paste only sanitized log snippets. Do not upload raw archives, secrets, tokens, or certificates. diff --git a/.github/ISSUE_TEMPLATE/compatibility_report.yml b/.github/ISSUE_TEMPLATE/compatibility_report.yml new file mode 100644 index 0000000..4af71d8 --- /dev/null +++ b/.github/ISSUE_TEMPLATE/compatibility_report.yml @@ -0,0 +1,39 @@ +name: Compatibility report +description: Report a tested platform or an explicit compatibility problem +title: "[Compatibility]: " +body: + - type: markdown + attributes: + value: | + Do not include credentials, internal names, certificates, or raw logs. Use [private vulnerability reporting](https://github.com/vartaxe/DriverAutomationTool/security/advisories/new) for security issues. If unavailable, contact [vartaxe@outlook.com](mailto:vartaxe@outlook.com) to arrange a private exchange. + - type: textarea + id: environment + attributes: + label: Environment + description: Driver Automation Tool version, OS / driver package context, Windows version, PowerShell version, and the relevant deployment phase. + validations: + required: true + - type: dropdown + id: platform + attributes: + label: Platform + options: + - Full Windows + - WinPE / OSD + - Intune / modern management + validations: + required: true + - type: textarea + id: policy + attributes: + label: Prerequisites and policy + description: Describe boot-state compatibility, driver package expectations, and any pre-requisites or blockers. Keep this sanitized and generic. + validations: + required: true + - type: textarea + id: evidence + attributes: + label: Results and sanitized evidence + description: Distinguish static checks, test automation, and live validation. Include the expected outcome, actual behavior, and the relevant exit or status code. + validations: + required: true diff --git a/.github/ISSUE_TEMPLATE/config.yml b/.github/ISSUE_TEMPLATE/config.yml new file mode 100644 index 0000000..34049b6 --- /dev/null +++ b/.github/ISSUE_TEMPLATE/config.yml @@ -0,0 +1,5 @@ +blank_issues_enabled: false +contact_links: + - name: Security vulnerability + url: https://github.com/vartaxe/DriverAutomationTool/security/advisories/new + about: Report vulnerabilities privately here. If unavailable, contact vartaxe@outlook.com to arrange a private exchange. diff --git a/.github/ISSUE_TEMPLATE/feature_request.yml b/.github/ISSUE_TEMPLATE/feature_request.yml new file mode 100644 index 0000000..ded25df --- /dev/null +++ b/.github/ISSUE_TEMPLATE/feature_request.yml @@ -0,0 +1,27 @@ +name: Feature request +description: Suggest a focused improvement for the Driver Automation Tool +title: "[Feature]: " +body: + - type: markdown + attributes: + value: | + Keep examples generic and do not disclose credentials or internal deployment details. Use [private vulnerability reporting](https://github.com/vartaxe/DriverAutomationTool/security/advisories/new) for security issues. If unavailable, contact [vartaxe@outlook.com](mailto:vartaxe@outlook.com) to arrange a private exchange. + - type: textarea + id: problem + attributes: + label: Problem + description: Describe the driver or deployment problem and why the current behavior is insufficient. + validations: + required: true + - type: textarea + id: proposal + attributes: + label: Proposed improvement + description: Explain the expected behavior and how it preserves secure defaults and repo validation expectations. + validations: + required: true + - type: textarea + id: alternatives + attributes: + label: Alternatives and validation + description: Describe alternatives considered and how the change could be tested without implying live validation that has not occurred. diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..3a626c3 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,6 @@ +version: 2 +updates: + - package-ecosystem: github-actions + directory: / + schedule: + interval: monthly diff --git a/.github/github-app.yml b/.github/github-app.yml new file mode 100644 index 0000000..f33ff50 --- /dev/null +++ b/.github/github-app.yml @@ -0,0 +1,3 @@ +automation: + auto_issue_session: true + remote_control: false \ No newline at end of file diff --git a/.github/pull_request_template.md b/.github/pull_request_template.md new file mode 100644 index 0000000..8fd1949 --- /dev/null +++ b/.github/pull_request_template.md @@ -0,0 +1,12 @@ +## Summary + +Describe the change and why it is needed. + +## Validation + +- [ ] Every `Tests\Test-*.ps1` regression harness passes on Windows PowerShell 5.1 +- [ ] Every `Tests\*.Tests.ps1` Pester 6.2.0 suite passes on Windows PowerShell 5.1 +- [ ] PowerShell parse checks pass for repo modules and script files +- [ ] Git diff is clean with no whitespace errors +- [ ] Documentation updated if behavior changed +- [ ] No credentials, internal values, or sensitive logs included diff --git a/.github/workflows/validate.yml b/.github/workflows/validate.yml index 74d48f8..77f65c8 100644 --- a/.github/workflows/validate.yml +++ b/.github/workflows/validate.yml @@ -22,6 +22,7 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 with: fetch-depth: 2 + persist-credentials: false - name: Check whitespace errors shell: powershell @@ -89,13 +90,11 @@ jobs: Install-Module Pester -RequiredVersion 6.2.0 -Scope CurrentUser -Force -ErrorAction Stop Import-Module Pester -RequiredVersion 6.2.0 -ErrorAction Stop $testRoot = Join-Path $env:GITHUB_WORKSPACE 'Tests' - $result = Invoke-Pester -Path @( - (Join-Path $testRoot 'CustomDismCancellation.Tests.ps1'), - (Join-Path $testRoot 'DismCancellation.Tests.ps1'), - (Join-Path $testRoot 'CustomCaptureGuards.Tests.ps1'), - (Join-Path $testRoot 'LifecycleSafety.Tests.ps1'), - (Join-Path $testRoot 'DriverInstallResults.Tests.ps1') - ) -Output Detailed -PassThru + $tests = @(Get-ChildItem -LiteralPath $testRoot -Filter '*.Tests.ps1' -File | Sort-Object Name) + if ($tests.Count -eq 0) { + throw 'No Pester regression suites were found.' + } + $result = Invoke-Pester -Path $tests.FullName -Output Detailed -PassThru if ($null -eq $result -or $result.Result -ne 'Passed' -or $result.TotalCount -eq 0 -or $result.FailedCount -gt 0 -or $result.FailedContainersCount -gt 0 -or $result.FailedBlocksCount -gt 0 -or $result.SkippedCount -gt 0 -or $result.NotRunCount -gt 0) { diff --git a/.vscode/extensions.json b/.vscode/extensions.json new file mode 100644 index 0000000..ae2462b --- /dev/null +++ b/.vscode/extensions.json @@ -0,0 +1,5 @@ +{ + "recommendations": [ + "ms-vscode.PowerShell" + ] +} diff --git a/.vscode/tasks.json b/.vscode/tasks.json new file mode 100644 index 0000000..01950ee --- /dev/null +++ b/.vscode/tasks.json @@ -0,0 +1,65 @@ +{ + "version": "2.0.0", + "tasks": [ + { + "label": "Validate PowerShell regression tests", + "dependsOrder": "sequence", + "dependsOn": [ + "Run script regression harnesses", + "Run Pester regression suites" + ], + "group": { + "kind": "test", + "isDefault": true + }, + "problemMatcher": [] + }, + { + "label": "Run script regression harnesses", + "type": "process", + "command": "${env:windir}\\System32\\WindowsPowerShell\\v1.0\\powershell.exe", + "args": [ + "-NoProfile", + "-NonInteractive", + "-ExecutionPolicy", + "Bypass", + "-Command", + "Get-ChildItem -LiteralPath '${workspaceFolder}\\Tests' -Filter 'Test-*.ps1' -File | Sort-Object Name | ForEach-Object { Write-Output \"Running $($_.Name)...\"; & '${env:windir}\\System32\\WindowsPowerShell\\v1.0\\powershell.exe' -NoProfile -NonInteractive -ExecutionPolicy Bypass -File $_.FullName; if ($LASTEXITCODE -ne 0) { throw \"$($_.Name) failed with exit code $LASTEXITCODE.\" } }" + ], + "options": { + "cwd": "${workspaceFolder}" + }, + "problemMatcher": [] + }, + { + "label": "Run Pester regression suites", + "type": "process", + "command": "${env:windir}\\System32\\WindowsPowerShell\\v1.0\\powershell.exe", + "args": [ + "-NoProfile", + "-NonInteractive", + "-ExecutionPolicy", + "Bypass", + "-Command", + "Import-Module Pester -RequiredVersion '6.2.0' -ErrorAction Stop; $Tests = @(Get-ChildItem -LiteralPath '${workspaceFolder}\\Tests' -Filter '*.Tests.ps1' -File | Sort-Object Name); if ($Tests.Count -eq 0) { throw 'No Pester regression suites were found.' }; $Result = Invoke-Pester -Path $Tests.FullName -Output Detailed -PassThru; if ($null -eq $Result -or $Result.Result -ne 'Passed' -or $Result.TotalCount -eq 0 -or $Result.FailedCount -gt 0 -or $Result.FailedContainersCount -gt 0 -or $Result.FailedBlocksCount -gt 0 -or $Result.SkippedCount -gt 0 -or $Result.NotRunCount -gt 0) { throw 'Pester regression suites did not fully pass.' }" + ], + "options": { + "cwd": "${workspaceFolder}" + }, + "problemMatcher": [] + }, + { + "label": "Check git whitespace", + "type": "process", + "command": "git", + "args": [ + "diff", + "--check" + ], + "options": { + "cwd": "${workspaceFolder}" + }, + "problemMatcher": [] + } + ] +}