Correct the judge-comparison label and remove stale dotnet-breaking-changes registry entries left by the rebase.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 8c45529b-2515-483d-9e51-e6c0b7cb6852
- Updated the skill description to clarify usage and restrictions for refactoring requests.
- Added new test cases for preserving serialized contracts in CustomerProfile.
- Introduced CustomerProfile class to support new test scenarios.
Replaces the shipped skill body with the validated v3 variant: judgment-first,
rigor proportional to blast radius, redundant catalog/list scaffolding removed.
~53% smaller (12,811->6,039 chars) with equal or better cross-family eval quality
and no measured regression. Description (929 chars) and all safety rules retained.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3c9f9823-7f2f-4f7d-9d1b-f2b9e7a20c60
Replaces the shipped skill body with the validated v3 variant: judgment-first,
rigor proportional to blast radius, redundant catalog/list scaffolding removed.
~53% smaller (12,811->6,039 chars) with equal or better cross-family eval quality
and no measured regression. Description (929 chars) and all safety rules retained.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3c9f9823-7f2f-4f7d-9d1b-f2b9e7a20c60
* fix: validate native Codex plugin support
Separate Codex-compatible plugin components from GitHub Copilot custom agents, validate Codex manifest fields and MCP shapes, and document the native agent installation boundary.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* fix: strengthen Codex plugin verification
Validate Codex MCP per-tool settings and add a pinned native smoke lane that installs the marketplace, discovers skills and MCP, and calls binlog_overview.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* fix: avoid restarting Codex MCP smoke client
Use the real tool call as the app-server initialization so the Linux smoke test does not start and tear down a redundant status client first.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* fix: harden Codex validation and smoke cleanup
Constrain smoke artifacts to a dedicated child directory, validate Codex manifest field shapes and required skill paths, and document the separate Agents SDK handoff model.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* fix: align Codex smoke and hooks parsing
Use the clean Codex installation's default provider for the direct MCP call and reject heterogeneous hooks arrays like the runtime parser.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* fix: verify every Codex plugin skill
Compare native skill discovery with the full repository inventory, match Codex lexical path rejection, and allow null optional MCP tool settings.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* fix: address Codex compatibility review
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Add automated per-plugin versioning (NBGV) with /version-bump + weekly backstop
WHY
Tools that surface skills (Copilot CLI, Claude Code, Codex, Cursor) read a
plugin's version directly from its checked-in manifest. With no versioning
discipline, a plugin's behavior can change while its advertised version stays
flat, so clients never learn to re-pull, and there is no human-readable signal
of what changed. We want correct, current versions in the repo with minimal
manual work and without bloating the marketplace clone.
WHAT
- Per-plugin semantic versioning via Nerdbank.GitVersioning (NBGV). Each plugin
owns a version.json whose pathFilters exclude the generated manifests and the
version.json itself, so version height tracks real content changes only.
- The computed version is materialized into the checked-in manifests
(plugin.json and .codex-plugin/plugin.json) so every consumer reads a current
value with no build step on their side.
- eng/version/Sync-PluginVersions.ps1 is the single workhorse. It resolves the
set of changed plugins from a git diff, computes each version with nbgv
(predicting the squash-merge height for PRs), and either reports or stamps.
AUTOMATIONS (two, low-touch by design)
- /version-bump: an admin/maintainer comments the command on a PR and the
affected plugins are stamped on the PR branch. Gated on collaborator
permission (admin/write/maintain); forks are rejected before any privileged
step. No other PRs are auto-modified.
- weekly-version-sync: a Monday backstop (and workflow_dispatch) that stamps any
drift on main, opens/updates a single bot PR, and explains the per-plugin
reason. This self-heals anything that merged without a bump.
We deliberately did NOT auto-edit contributor PRs or add a noisy advisory
comment bot; maintainers stay in control and the signal stays clean.
SECURITY (multi-model adversarial review: GPT-5.5 + Gemini 3.1 Pro)
- Supply chain (High, both models): dotnet tool restore would have honored a
nuget.config authored in the PR tree, letting an attacker remap the nbgv
package source to a malicious feed and run code in the privileged
contents:write context. Mitigated with a trusted eng/version/nuget.config
(clear + nuget.org-only + packageSourceMapping), overlaid from main and used
via --configfile so PR-supplied configs are ignored. No nuget.config is
tracked in the repo today, so this path was genuinely exploitable.
- TOCTOU (Medium): /version-bump now checks out the authorized head SHA rather
than the mutable branch name; a racing push fails non-fast-forward, which is
the safe outcome.
- Injection: Set-ManifestVersion uses a MatchEvaluator (not a replacement
string) so a "$"-bearing version cannot re-expand, plus a strict
major.minor.patch guard that throws on a malformed base, leaving manifests
untouched.
- A base-only version.json bump (0.1 -> 0.2) is correctly detected and stamped.
VERIFIED
End-to-end against a real NBGV git harness: content-scoped predict, base-only
bump -> x.y.0, docs-only -> [], weekly drift stamping, malformed-base guard,
and --configfile restore (exit 0). actionlint passes on both workflows.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Address Copilot review feedback
- Add missing plugins/dotnet-test-migration/version.json so it participates
in versioning (it was the only plugin without one; manifests are at 0.1.0).
- CONTRIBUTING: the two manifests are not byte-identical; say the version is
duplicated across two manifest files instead.
- weekly-version-sync: include version.json in commit attribution so a
base-only bump is explained rather than showing 'no attributable commits'.
- Get-NbgvInfo: capture nbgv stderr and include it in the thrown error so CI
failures are diagnosable, while keeping stdout clean for JSON parsing.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Add csharp-development skill and update CODEOWNERS and README.md
- Introduced a new skill for C# development guidance.
- Updated CODEOWNERS to include reviewers for the new skill.
- Modified README.md to list the new csharp-development skill.
- Added evaluation scenarios for the csharp-development skill.
* Refactor C# evaluation scenarios to enhance production code review and validation guidance
* Refactor production code review scenarios to improve clarity and focus on async error handling
* Update CODEOWNERS to reflect current ownership and streamline reviewer assignments
* Remove csharp-development skill documentation and evaluation tests
* Remove csharp-development skill from README
* Fix formatting in Constants.g.cs by adding missing semicolon
* Revert Constants.g.cs to main
* Remove csharp-development skill from CODEOWNERS
* Potential fix for pull request finding
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* Update CODEOWNERS to include additional reviewers for dotnet-ai skills
* Move dotnet skills to dotnet-util to keep dotnet plugin focused and targeted.
* Add CODEOWNERS, SKILL.md, package-types.md, and publish-workflow.md for NuGet trusted publishing; implement eval.yaml for dotnet-pinvoke and dotnet-util skills
* Potential fix for pull request finding
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* Potential fix for pull request finding
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* Update README files to enhance plugin descriptions and remove outdated LSP section
* Rename repository title from 'dotnet' to 'dotnet-util' in README.md for clarity.
* Refine README.md to clarify included .NET skills and remove redundant descriptions
* Add 'dotnet-util' plugin for utility skills in .NET development
* Potential fix for pull request finding
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* Add 'dotnet-util' plugin for utility skills in .NET development
* Add dotnet-util to Codex marketplace manifest
* Align dotnet-util marketplace descriptions
* Refactor CODEOWNERS and update README for nuget-trusted-publishing; add evaluation scenarios and workflow template for trusted publishing
* Add P/Invoke diagnostics and type mapping references; implement NuGet trusted publishing setup
- Created diagnostics.md for common pitfalls and failure modes in P/Invoke.
- Added type-mapping.md for native-to-.NET type mappings.
- Introduced nuget-trusted-publishing skill for setting up OIDC-based NuGet publishing.
- Added package-types.md detailing structural requirements for various NuGet package types.
- Created publish-workflow.md as a template for GitHub Actions workflows for NuGet publishing.
* Add evaluation YAML files for csharp-scripts, dotnet-pinvoke, and nuget-trusted-publishing skills
* Potential fix for pull request finding
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* Complete nuget-trusted-publishing move: remove from dotnet, add to dotnet-specialized README
* Potential fix for pull request finding
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* Potential fix for pull request finding
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* Remove eval.vally.yaml and eval.yaml files for nuget-trusted-publishing skill
* Potential fix for pull request finding
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* Potential fix for pull request finding
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* Potential fix for pull request finding
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* Add NuGet trusted publishing skill and related references
- Introduced `nuget-trusted-publishing` skill for setting up OIDC-based trusted publishing on GitHub Actions.
- Added detailed documentation in SKILL.md covering prerequisites, process, safety rules, and troubleshooting.
- Created `package-types.md` to outline structural requirements for various NuGet package types.
- Developed `publish-workflow.md` as a template for GitHub Actions workflows for NuGet publishing.
- Removed obsolete `dotnet-specialized` plugin and updated `dotnet` plugin description.
- Added evaluation tests for `nuget-trusted-publishing` skill to ensure proper guidance for users.
- Implemented evaluation tests for `dotnet-pinvoke` and `csharp-scripts` skills to validate functionality.
* Update dotnet plugin description to include high-level .NET development skills
* Add NuGet trusted publishing and P/Invoke documentation
- Introduced type mapping reference for native-to-.NET types in dotnet-pinvoke.
- Added a comprehensive guide for setting up NuGet trusted publishing using OIDC in GitHub Actions.
- Created a reference document detailing structural requirements for various NuGet package types.
- Provided a template for GitHub Actions workflow for publishing NuGet packages with trusted publishing.
- Implemented evaluation scenarios for testing the dotnet-pinvoke and nuget-trusted-publishing skills, including prompts and assertions for expected outputs.
* Potential fix for pull request finding
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* Potential fix for pull request finding
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* Potential fix for pull request finding
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* Potential fix for pull request finding
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* Add CODEOWNERS entries for setup-local-sdk
* Potential fix for pull request finding
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* Potential fix for pull request finding
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* Update dotnet README to list setup-local-sdk skill
* Add setup-local-sdk to skills section in README
* Potential fix for pull request finding
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* Potential fix for pull request finding
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
* Rebase setup-local-sdk skill
Replay PR #508 onto current main and address the remaining setup-local-sdk review feedback. The install examples now use fail-fast temporary downloads, the team scripts preserve existing global.json content, and eval assertions cover the critical paths/version/workload behavior.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Address setup-local-sdk review comments
Add the missing skill license metadata and fix the PowerShell .gitignore regex examples so they correctly detect an existing .dotnet/ entry.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Stabilize setup-local-sdk evals
Reduce overfit-prone assertions, make incompatible host handling explicit, configure base SDK resolution before slow workload installs, and tighten exact-version/team-script validation.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Address setup-local-sdk follow-up review
Include the shared dotnet skill reviewer team in CODEOWNERS, make .gitignore appends newline-safe, and tighten the incompatible-host eval to reward stopping before local install commands.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Tighten exact local SDK eval
Measure project-level SDK resolution and exact roll-forward behavior using global.json artifact assertions so the scenario distinguishes PATH-based local installs from SDK paths setup.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Address install script review feedback
Use the documented lowercase dotnet-install quality value and call out both bash and PowerShell official install script URLs.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Increase team script eval timeout
Give the team install script scenario the same realistic long-running timeout as other scenarios that install preview SDK bits.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Add Windows local SDK check
Document the PowerShell equivalent for detecting an existing local SDK and give exact SDK installs enough time to complete in eval.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Stabilize team script eval
Focus the team script scenario on script/config generation, create reproducible setup guidance before long downloads, and avoid brittle transcript assertions.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Make mktemp usage portable
Use BSD/macOS-compatible mktemp templates in setup-local-sdk bash snippets and generated team install script.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
The Codex CLI requires .codex-plugin/plugin.json as the plugin manifest
entry point. Without it, 'codex plugin add' fails with 'missing plugin.json'
even though the marketplace listing works.
This adds .codex-plugin/plugin.json to all 14 plugin directories, with paths
relative to the plugin root per the Codex docs. Also updates the agents
marketplace to use dotnet-aspnetcore (per #711 rename) and adds missing
dotnet-blazor and dotnet11 entries.
Fixes#578Fixes#724
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Due to the behavior of dotnet SDK resolution when running in repos which use a global.json, we are not gaurenteed that the choosen SDK will be new enough to support the dotnet dnx command which we were using to install and run the roslyn-language-server. Instead, we will ship our own global.json and configure the current working directory to be the plugin directory.
Claude Code auto-discovers `.lsp.json` at plugin root and expects a
schema that differs from Copilot CLI's `lsp.json`:
- No outer `lspServers` wrapper in the external file (the wrapper is
only used when defining LSP servers inline in `plugin.json`).
- Required field is `extensionToLanguage`, not `fileExtensions`.
Without this file, Claude Code silently rejects the existing
`lsp.json` (Copilot CLI shape) and the Roslyn language server is
never registered — `/reload-plugins` reports `0 plugin LSP servers`.
After adding `.lsp.json`, the count becomes `1 plugin LSP server`
and `findReferences`, `goToImplementation`, etc. work end-to-end.
The existing `lsp.json` is left untouched so Copilot CLI continues
to work; the two hosts read different filenames and never see each
other's config.
References:
- https://code.claude.com/docs/en/plugins-reference (lspServers,
external `.lsp.json` format, required fields)
- https://docs.github.com/en/copilot/how-tos/copilot-cli/set-up-copilot-cli/add-lsp-servers (Copilot CLI uses `lsp.json` with `lspServers` wrapper and `fileExtensions`)
Signed-off-by: Roman Głogowski <roman.glogowski@volue.com>