Compatibility and trust¶
A checkmark means the capability is exercised by the default-branch CI pipeline. It is not a promise about platforms or versions outside the matrix below. Follow the evidence links to inspect the executable test projects and workflow history.
Runtime and environment¶
| Capability | Verified value | Status |
|---|---|---|
| Target framework | net10.0 |
✅ CI verified |
| .NET SDK | 10.0.401 with latestPatch roll-forward |
✅ CI verified |
| Test runner | Microsoft.Testing.Platform |
✅ CI verified |
| CI operating system | GitHub-hosted ubuntu-latest |
✅ CI verified |
| Container runtime | Docker API through Testcontainers on the GitHub runner | ✅ CI verified |
| Windows and macOS | Not in the CI matrix | Not claimed |
| Podman | Supported as a Docker-compatible local runtime | Not continuously verified |
Test frameworks¶
Each framework consumer is built and run in full, filtered, intentionally failing and skipped modes. CI also verifies once-per-run startup, teardown and client cleanup.
| Framework | Version | Verification | Evidence |
|---|---|---|---|
| xUnit v3 | 4.0.1 |
✅ CI verified | Consumer project |
| NUnit | 5.0.0 |
✅ CI verified | Consumer project |
| MSTest | 4.4.1 |
✅ CI verified | Consumer project |
| TUnit | 1.70.1 |
✅ CI verified | Consumer project |
Release package surface¶
Every listed package must appear in the release manifest, produce both package and symbol artifacts, restore from an isolated local feed, and compile in the package smoke test before publication.
Executable scenarios¶
| CI suite | What it verifies | Evidence |
|---|---|---|
| Core | Lifecycle, correlation and failure reporting | ✅ Test project |
| Hosting | ASP.NET Core, HTTP, telemetry and WireMock | ✅ Test project |
| Custom containers | User-supplied Testcontainers dependencies | ✅ Test project |
| Object storage composition | MinIO API composition example | ✅ Test project |
| OIDC | Discovery, JWKS and signed test tokens | ✅ Test project |
| Test time | Application time and hosted workers | ✅ Test project |
| PostgreSQL | PostgreSQL container and native queries | ✅ Test project |
| SQL Server | SQL Server container and native queries | ✅ Test project |
| MongoDB | Replica set and native document queries | ✅ Test project |
| MySQL | MySQL container and native queries | ✅ Test project |
| Redis | Redis container and native client | ✅ Test project |
| RabbitMQ | Publishing, routing and correlated observation | ✅ Test project |
| Azure Service Bus | Queues, topics, scheduling and settlement | ✅ Test project |
| Kafka | Publishing, consuming and correlated observation | ✅ Test project |
| OrderService composition | API, brokers, database, telemetry and fakes | ✅ Test project |
| API and worker composition | Named API and Generic Host worker | ✅ Test project |
Security and release controls¶
| Control | Status | Public evidence |
|---|---|---|
| Pull-request CI and package verification | ✅ Enforced | CI workflow |
| Static analysis | ✅ CodeQL | CodeQL runs |
| Dependency changes | ✅ Reviewed on pull requests | Dependency review workflow |
| Supply-chain posture | ✅ Independently scored | OpenSSF Scorecard |
| NuGet authentication | ✅ Environment-bound OIDC; no long-lived API key | Release security |
| Actions dependencies | ✅ Full commit SHA pins | Workflow sources |
| Vulnerability reporting | ✅ Private reporting enabled | Security policy |
Security scanners reduce risk but cannot prove the absence of vulnerabilities. See the security policy to report an issue privately.