Skip to content

pr.yaml: write protected config files as UTF-8 without BOM#57

Merged
Chris-Wolfgang merged 1 commit into
mainfrom
fix/pr-yaml-bom-encoding-on-protected-config-fetch
May 16, 2026
Merged

pr.yaml: write protected config files as UTF-8 without BOM#57
Chris-Wolfgang merged 1 commit into
mainfrom
fix/pr-yaml-bom-encoding-on-protected-config-fetch

Conversation

@Chris-Wolfgang

Copy link
Copy Markdown
Owner

Backport of repo-template#339.

The 'Fetch trusted configuration files from main branch' step writes the protected configs back via Out-File -Encoding UTF8 (BOM-prefixed). The .NET analyzer engine appears to ignore BOM-prefixed .editorconfig files, so project severity overrides don't apply on CI — analyzers fire at default severity and TreatWarningsAsErrors escalates findings that pass locally.

This is a 4-line workflow-only change: UTF8UTF8NoBOM at the four call sites. PowerShell 6+ supports the encoding token; shell: pwsh runners use PS 7+, so it's safe.

Diagnosed against In-memory-Logger PR #32 / run 24996715587.

🤖 Generated with Claude Code

Backport of repo-template PR #339. The 'Fetch trusted configuration files
from main branch' step writes .editorconfig / Directory.Build.props /
BannedSymbols.txt back via 'Out-File -Encoding UTF8' which writes UTF-8
*with* BOM. The .NET analyzer engine appears to ignore .editorconfig
files prefixed by a BOM, so project-level severity overrides don't apply
on CI even though they apply locally — analyzers fire at default severity
and TreatWarningsAsErrors then escalates them to errors.

Switch to 'Out-File -Encoding UTF8NoBOM' (PS 6+; the runner uses pwsh).

Diagnosed against Chris-Wolfgang/In-memory-Logger PR #32 / run
24996715587. See Chris-Wolfgang/repo-template#339 for the full write-up.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings May 9, 2026 18:14

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the CI workflow to write “trusted” configuration files fetched from main as UTF-8 without a BOM, preventing .editorconfig/analyzer settings from being ignored on CI when those files are rewritten during the security-hardening step.

Changes:

  • Switch Out-File encoding from UTF8 (BOM) to UTF8NoBOM at the four PowerShell write sites in the Windows job.

Comment thread .github/workflows/pr.yaml

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 1 out of 1 changed files in this pull request and generated no new comments.

@Chris-Wolfgang Chris-Wolfgang merged commit 98d9e8e into main May 16, 2026
15 of 16 checks passed
@Chris-Wolfgang Chris-Wolfgang deleted the fix/pr-yaml-bom-encoding-on-protected-config-fetch branch May 16, 2026 00:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants