Compatibility and trust

CI Documentation OpenSSF Scorecard

A checkmark means the capability is exercised by the default-branch CI pipeline. It is not a promise about platforms or versions outside the matrix below. Follow the evidence links to inspect the executable test projects and workflow history.

Runtime and environment

Capability Verified value Status
Target framework net10.0 ✅ CI verified
.NET SDK 10.0.401 with latestPatch roll-forward ✅ CI verified
Test runner Microsoft.Testing.Platform ✅ CI verified
CI operating system GitHub-hosted ubuntu-latest ✅ CI verified
Container runtime Docker API through Testcontainers on the GitHub runner ✅ CI verified
Windows and macOS Not in the CI matrix Not claimed
Podman Supported as a Docker-compatible local runtime Not continuously verified

Test frameworks

Each framework consumer is built and run in full, filtered, intentionally failing and skipped modes. CI also verifies once-per-run startup, teardown and client cleanup.

Framework Version Verification Evidence
xUnit v3 4.0.1 ✅ CI verified Consumer project
NUnit 5.0.0 ✅ CI verified Consumer project
MSTest 4.4.1 ✅ CI verified Consumer project
TUnit 1.70.1 ✅ CI verified Consumer project

Release package surface

Every listed package must appear in the release manifest, produce both package and symbol artifacts, restore from an isolated local feed, and compile in the package smoke test before publication.

Package Area Purpose Behavioral evidence
StoveDotnet Core Builder, lifecycle, test scope and correlation ✅ Core
StoveDotnet.AspNetCore Applications ASP.NET Core hosting and DI access ✅ Hosting
StoveDotnet.Azure.ServiceBus Messaging Queues, topics, subscriptions and scheduling ✅ Azure Service Bus
StoveDotnet.Containers Infrastructure User-supplied dependency containers ✅ Custom containers
StoveDotnet.Hosting Applications Named Generic Host workers ✅ API and worker composition
StoveDotnet.Http Applications Typed HTTP calls and assertions ✅ Hosting
StoveDotnet.Kafka Messaging Kafka publishing and observation ✅ Kafka
StoveDotnet.MongoDb Databases MongoDB replica set and native client ✅ MongoDB
StoveDotnet.MySql Databases MySQL and native client ✅ MySQL
StoveDotnet.Oidc Infrastructure OIDC discovery, keys and signed tokens ✅ OIDC
StoveDotnet.Postgres Databases PostgreSQL and native client ✅ PostgreSQL
StoveDotnet.RabbitMq Messaging RabbitMQ publishing and observation ✅ RabbitMQ
StoveDotnet.Redis Infrastructure Redis and native client ✅ Redis
StoveDotnet.SqlServer Databases SQL Server and native client ✅ SQL Server
StoveDotnet.Telemetry Diagnostics OTLP trace and log collection ✅ OrderService composition
StoveDotnet.Time Infrastructure Controllable application time ✅ Test time
StoveDotnet.WireMock Third-party APIs In-process HTTP fakes ✅ Hosting

Executable scenarios

CI suite What it verifies Evidence
Core Lifecycle, correlation and failure reporting ✅ Test project
Hosting ASP.NET Core, HTTP, telemetry and WireMock ✅ Test project
Custom containers User-supplied Testcontainers dependencies ✅ Test project
Object storage composition MinIO API composition example ✅ Test project
OIDC Discovery, JWKS and signed test tokens ✅ Test project
Test time Application time and hosted workers ✅ Test project
PostgreSQL PostgreSQL container and native queries ✅ Test project
SQL Server SQL Server container and native queries ✅ Test project
MongoDB Replica set and native document queries ✅ Test project
MySQL MySQL container and native queries ✅ Test project
Redis Redis container and native client ✅ Test project
RabbitMQ Publishing, routing and correlated observation ✅ Test project
Azure Service Bus Queues, topics, scheduling and settlement ✅ Test project
Kafka Publishing, consuming and correlated observation ✅ Test project
OrderService composition API, brokers, database, telemetry and fakes ✅ Test project
API and worker composition Named API and Generic Host worker ✅ Test project

Security and release controls

Control Status Public evidence
Pull-request CI and package verification ✅ Enforced CI workflow
Static analysis ✅ CodeQL CodeQL runs
Dependency changes ✅ Reviewed on pull requests Dependency review workflow
Supply-chain posture ✅ Independently scored OpenSSF Scorecard
NuGet authentication ✅ Environment-bound OIDC; no long-lived API key Release security
Actions dependencies ✅ Full commit SHA pins Workflow sources
Vulnerability reporting ✅ Private reporting enabled Security policy

Security scanners reduce risk but cannot prove the absence of vulnerabilities. See the security policy to report an issue privately.