From 17ead55ddae5750d1d4c53231a5584cab2801307 Mon Sep 17 00:00:00 2001 From: Ivan Bogatec Date: Sat, 19 Sep 2026 13:24:52 +0200 Subject: [PATCH 1/2] Add GitHub Actions CI/CD workflows and repository templates --- .editorconfig | 61 ++++++++++++++++ .github/ISSUE_TEMPLATE/bug_report.md | 32 +++++++++ .github/ISSUE_TEMPLATE/feature_request.md | 19 +++++ .github/PULL_REQUEST_TEMPLATE.md | 26 +++++++ .github/dependabot.yml | 31 ++++++++ .github/workflows/ci.yml | 86 +++++++++++++++++++++++ .github/workflows/codeql.yml | 43 ++++++++++++ Readme.md | 18 +++++ 8 files changed, 316 insertions(+) create mode 100644 .editorconfig create mode 100644 .github/ISSUE_TEMPLATE/bug_report.md create mode 100644 .github/ISSUE_TEMPLATE/feature_request.md create mode 100644 .github/PULL_REQUEST_TEMPLATE.md create mode 100644 .github/dependabot.yml create mode 100644 .github/workflows/ci.yml create mode 100644 .github/workflows/codeql.yml diff --git a/.editorconfig b/.editorconfig new file mode 100644 index 0000000..460b80e --- /dev/null +++ b/.editorconfig @@ -0,0 +1,61 @@ +# Top-most EditorConfig file +root = true + +# Default rules for all files +[*] +indent_style = space +indent_size = 4 +end_of_line = lf +charset = utf-8 +trim_trailing_whitespace = true +insert_final_newline = true + +# Markdown and YAML files +[*.{md,yml,yaml}] +indent_size = 4 +trim_trailing_whitespace = false + +# XML, CSPROJ, SLN, and JSON files +[*.{csproj,props,targets,xml,config,runsettings,json}] +indent_size = 4 + +# C# Code Styling and Quality Rules +[*.cs] +# Namespace preferences: file-scoped namespaces (C# 10+) +csharp_style_namespace_declarations = file_scoped:suggestion + +# 'using' directive preferences +dotnet_sort_system_directives_first = true +csharp_using_directive_placement = outside_namespace:suggestion +dotnet_diagnostic.IDE0005.severity = suggestion # Remove unused using directives + +# 'var' preferences +csharp_style_var_for_built_in_types = false:suggestion +csharp_style_var_when_type_is_apparent = true:suggestion +csharp_style_var_elsewhere = true:suggestion + +# Expression-bodied members +csharp_style_expression_bodied_methods = when_on_single_line:suggestion +csharp_style_expression_bodied_constructors = false:suggestion +csharp_style_expression_bodied_operators = when_on_single_line:suggestion +csharp_style_expression_bodied_properties = true:suggestion +csharp_style_expression_bodied_indexers = true:suggestion +csharp_style_expression_bodied_accessors = true:suggestion +csharp_style_expression_bodied_lambdas = true:suggestion + +# Pattern matching preferences +csharp_style_pattern_matching_over_is_syntax = true:suggestion +csharp_style_pattern_matching_over_as_syntax = true:suggestion +csharp_style_prefer_pattern_matching = true:suggestion +csharp_style_prefer_switch_expression = true:suggestion + +# Null-checking preferences +csharp_style_prefer_null_check_over_type_check = true:suggestion +csharp_style_conditional_delegate_call = true:suggestion + +# Modifier preferences +csharp_preferred_modifier_order = public,protected,internal,private,static,abstract,virtual,override,sealed,readonly,volatile,async:suggestion + +# Code block preferences +csharp_prefer_braces = true:suggestion +csharp_preserve_single_line_blocks = true:none diff --git a/.github/ISSUE_TEMPLATE/bug_report.md b/.github/ISSUE_TEMPLATE/bug_report.md new file mode 100644 index 0000000..9305290 --- /dev/null +++ b/.github/ISSUE_TEMPLATE/bug_report.md @@ -0,0 +1,32 @@ +--- +name: Bug Report +about: Create a report to help reproduce and fix a defect +title: "[BUG] " +labels: ["bug"] +assignees: "" +--- + +**Describe the Bug** +A clear and concise description of what the bug is. + +**To Reproduce** +Steps to reproduce the behavior: +1. Go to '...' +2. Click on '....' +3. Scroll down to '....' +4. See error + +**Expected Behavior** +A clear and concise description of what you expected to happen. + +**Actual Behavior / Error Logs** +Include stack trace, error logs, or browser console output if available. + +**Screenshots** +If applicable, add screenshots to help explain your problem. + +**Environment (please complete the following information):** + - OS: [e.g. Ubuntu 24.04, Windows 11, macOS Sequoia] + - .NET SDK Version: [e.g. 10.0.100] + - Browser (if applicable): [e.g. Chrome, Firefox] + - Database: SQL Server 2025 (Docker) diff --git a/.github/ISSUE_TEMPLATE/feature_request.md b/.github/ISSUE_TEMPLATE/feature_request.md new file mode 100644 index 0000000..20f23f2 --- /dev/null +++ b/.github/ISSUE_TEMPLATE/feature_request.md @@ -0,0 +1,19 @@ +--- +name: Feature Request +about: Suggest an idea or architectural enhancement for this project +title: "[FEATURE] " +labels: ["enhancement"] +assignees: "" +--- + +**Is your feature request related to a problem? Please describe.** +A clear and concise description of what the problem is. Ex. I'm always frustrated when [...] + +**Describe the Solution You'd Like** +A clear and concise description of what you want to happen. + +**Describe Alternatives You've Considered** +A clear and concise description of any alternative solutions or features you've considered. + +**Additional Context** +Add any other context, architectural diagrams, or screenshots about the feature request here. diff --git a/.github/PULL_REQUEST_TEMPLATE.md b/.github/PULL_REQUEST_TEMPLATE.md new file mode 100644 index 0000000..a8e49d2 --- /dev/null +++ b/.github/PULL_REQUEST_TEMPLATE.md @@ -0,0 +1,26 @@ +## Description + + +## Type of Change + +- [ ] ๐Ÿ› Bug fix (non-breaking change fixing an issue) +- [ ] โœจ New feature (non-breaking change adding functionality) +- [ ] ๐Ÿ’ฅ Breaking change (fix or feature causing existing functionality to change) +- [ ] โ™ป๏ธ Refactoring / Code cleanup (no functional change) +- [ ] ๐Ÿ“ Documentation update +- [ ] ๐Ÿงช Test suite enhancement + +## Quality Checklist +- [ ] My code follows the project's code style and formatting standards (`.editorconfig`). +- [ ] All unit tests pass locally (`dotnet test BionicSquare.UnitTests`). +- [ ] All integration tests pass locally (`dotnet test BionicSquare.IntegrationTests`). +- [ ] Code builds with **0 warnings** and **0 errors** (`dotnet build`). +- [ ] I have added/updated unit or integration tests to cover my changes. +- [ ] Unused `using` directives have been removed. +- [ ] Relevant documentation has been updated. + +## Screenshots / Visual Evidence (if applicable) + + +## Related Issues / Tickets + diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..b77c7b5 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,31 @@ +version: 2 +updates: + # Maintain NuGet package dependencies across all .NET projects + - package-ecosystem: "nuget" + directory: "/" + schedule: + interval: "weekly" + day: "monday" + time: "07:00" + open-pull-requests-limit: 10 + commit-message: + prefix: "deps" + include: "scope" + labels: + - "dependencies" + - "nuget" + + # Maintain GitHub Actions dependencies + - package-ecosystem: "github-actions" + directory: "/" + schedule: + interval: "weekly" + day: "monday" + time: "07:00" + open-pull-requests-limit: 5 + commit-message: + prefix: "ci" + include: "scope" + labels: + - "dependencies" + - "github-actions" diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml new file mode 100644 index 0000000..2af3227 --- /dev/null +++ b/.github/workflows/ci.yml @@ -0,0 +1,86 @@ +name: Continuous Integration + +on: + push: + branches: [ master, main ] + pull_request: + branches: [ master, main ] + workflow_dispatch: + +permissions: + contents: read + actions: read + +jobs: + build-and-test: + name: Build & Test (Unit + Integration) + runs-on: ubuntu-latest + + steps: + - name: Checkout Repository + uses: actions/checkout@v4 + + - name: Setup .NET SDK + uses: actions/setup-dotnet@v4 + with: + dotnet-version: '10.0.x' + + - name: Restore Dependencies + run: dotnet restore BionicSquareBook.sln + + - name: Build Solution + run: dotnet build BionicSquareBook.sln --no-restore --configuration Release + + - name: Run Unit Tests with Coverage + run: | + dotnet test BionicSquare.UnitTests/BionicSquare.UnitTests.csproj \ + --configuration Release \ + --no-build \ + --settings coverlet.runsettings \ + --collect:"XPlat Code Coverage" \ + --results-directory ./TestResults/UnitTests \ + --logger "trx;LogFileName=unit_tests.trx" + + - name: Run Integration Tests with Coverage (Testcontainers SQL Server 2025) + run: | + dotnet test BionicSquare.IntegrationTests/BionicSquare.IntegrationTests.csproj \ + --configuration Release \ + --no-build \ + --settings coverlet.runsettings \ + --collect:"XPlat Code Coverage" \ + --results-directory ./TestResults/IntegrationTests \ + --logger "trx;LogFileName=integration_tests.trx" + + - name: Install ReportGenerator Tool + run: dotnet tool install --global dotnet-reportgenerator-globaltool + + - name: Generate Code Coverage Report & Summary + run: | + reportgenerator \ + -reports:"./TestResults/**/coverage.cobertura.xml" \ + -targetdir:"./CoverageReport" \ + -reporttypes:"Html;MarkdownSummaryGithub" + + - name: Publish Coverage Summary to Job Summary + if: always() + run: | + if [ -f "./CoverageReport/SummaryGithub.md" ]; then + echo "## ๐Ÿ“Š Code Coverage Summary" >> $GITHUB_STEP_SUMMARY + cat ./CoverageReport/SummaryGithub.md >> $GITHUB_STEP_SUMMARY + fi + + - name: Upload HTML Coverage Report Artifact + uses: actions/upload-artifact@v4 + if: always() + with: + name: code-coverage-report + path: ./CoverageReport + retention-days: 14 + + - name: Upload Test Results Artifacts (.trx) + uses: actions/upload-artifact@v4 + if: always() + with: + name: test-results + path: ./TestResults/**/*.trx + retention-days: 14 diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml new file mode 100644 index 0000000..ef4e63d --- /dev/null +++ b/.github/workflows/codeql.yml @@ -0,0 +1,43 @@ +name: "CodeQL Security Analysis" + +on: + push: + branches: [ master, main ] + pull_request: + branches: [ master, main ] + schedule: + - cron: '0 6 * * 1' # Runs weekly on Mondays at 06:00 UTC + workflow_dispatch: + +permissions: + actions: read + contents: read + security-events: write + +jobs: + analyze: + name: CodeQL Analysis (C#) + runs-on: ubuntu-latest + timeout-minutes: 15 + + steps: + - name: Checkout Repository + uses: actions/checkout@v4 + + - name: Setup .NET SDK + uses: actions/setup-dotnet@v4 + with: + dotnet-version: '10.0.x' + + - name: Initialize CodeQL + uses: github/codeql-action/init@v3 + with: + languages: csharp + + - name: Build Solution + run: dotnet build BionicSquareBook.sln --configuration Release + + - name: Perform CodeQL Analysis + uses: github/codeql-action/analyze@v3 + with: + category: "/language:csharp" diff --git a/Readme.md b/Readme.md index 42da105..c482be0 100644 --- a/Readme.md +++ b/Readme.md @@ -1,6 +1,8 @@ # BionicSquareBook [![.NET 10](https://img.shields.io/badge/.NET-10.0-512BD4?style=flat&logo=dotnet)](https://dotnet.microsoft.com/) +[![CI](https://github.com/ibogatec/BionicSquareBook/actions/workflows/ci.yml/badge.svg)](https://github.com/ibogatec/BionicSquareBook/actions/workflows/ci.yml) +[![CodeQL](https://github.com/ibogatec/BionicSquareBook/actions/workflows/codeql.yml/badge.svg)](https://github.com/ibogatec/BionicSquareBook/actions/workflows/codeql.yml) [![Entity Framework Core](https://img.shields.io/badge/EF%20Core-10.0-512BD4?style=flat&logo=nuget)](https://docs.microsoft.com/ef/core/) [![SQL Server 2025](https://img.shields.io/badge/SQL%20Server-2025-CC292B?style=flat&logo=microsoftsqlserver)](https://www.microsoft.com/sql-server) [![Bootstrap 5](https://img.shields.io/badge/Bootstrap-5.3.8-7952B3?style=flat&logo=bootstrap)](https://getbootstrap.com/) @@ -143,6 +145,18 @@ graph TD ```text BionicSquareBook/ +โ”œโ”€โ”€ .github/ # GitHub configurations and DevOps automation +โ”‚ โ”œโ”€โ”€ ISSUE_TEMPLATE/ +โ”‚ โ”‚ โ”œโ”€โ”€ bug_report.md # Standardized bug reporting template +โ”‚ โ”‚ โ””โ”€โ”€ feature_request.md # Feature request & enhancement proposal template +โ”‚ โ”œโ”€โ”€ workflows/ +โ”‚ โ”‚ โ”œโ”€โ”€ ci.yml # GitHub Actions CI (Build, Unit & Integration Tests, Coverage Summary) +โ”‚ โ”‚ โ””โ”€โ”€ codeql.yml # CodeQL Static Application Security Testing (SAST) +โ”‚ โ”œโ”€โ”€ dependabot.yml # Dependabot configuration (NuGet & GitHub Actions updates) +โ”‚ โ””โ”€โ”€ PULL_REQUEST_TEMPLATE.md # Engineering pull request quality checklist +โ”‚ +โ”œโ”€โ”€ .editorconfig # Code style and analyzer standards +โ”‚ โ”œโ”€โ”€ BionicSquare.Business/ # Business Logic Layer (Services & Validation) โ”‚ โ”œโ”€โ”€ Services/ โ”‚ โ”‚ โ”œโ”€โ”€ ApplicationUserService.cs @@ -215,6 +229,10 @@ BionicSquareBook/ - **ORM**: Entity Framework Core 10.0 (SQL Server provider, Tools, Design) - **Database**: Microsoft SQL Server 2025 (via Docker) - **Authentication / Security**: ASP.NET Core Identity with role-based authorization and Cookie Authentication +- **DevOps & CI/CD**: + - GitHub Actions Continuous Integration (multi-stage build, test, and report summary) + - GitHub CodeQL Static Application Security Testing (SAST) + - Dependabot automated NuGet and Actions dependency updates - **Front-end UI & Styling**: - Bootstrap 5.3.8 + Bootstrap Icons 1.13.1 - Custom dark theme with vibrant emerald-green highlights (`#1DB954` / `#17A34A`) From 85d112bf63a64c43714949e3230bd2e8b23e4e4c Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Sat, 19 Sep 2026 11:27:33 +0000 Subject: [PATCH 2/2] ci(deps): bump actions/checkout from 4 to 7 Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 7. - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](https://github.com/actions/checkout/compare/v4...v7) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] --- .github/workflows/ci.yml | 2 +- .github/workflows/codeql.yml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 2af3227..b880021 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -18,7 +18,7 @@ jobs: steps: - name: Checkout Repository - uses: actions/checkout@v4 + uses: actions/checkout@v7 - name: Setup .NET SDK uses: actions/setup-dotnet@v4 diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index ef4e63d..68c6f84 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -22,7 +22,7 @@ jobs: steps: - name: Checkout Repository - uses: actions/checkout@v4 + uses: actions/checkout@v7 - name: Setup .NET SDK uses: actions/setup-dotnet@v4