diff --git a/.gitattributes b/.gitattributes index ae4d0f4..d1c9732 100644 --- a/.gitattributes +++ b/.gitattributes @@ -3,16 +3,3 @@ # who committed it, that gate passes or fails based on the author's machine instead of the code. # Every tracked text file is already LF, and .editorconfig's end_of_line matches. * text=auto eol=lf - -# Spreadsheet fixtures are ZIP (xlsx/xlsm/xlsb) and CFB (xls) containers. Never let text=auto's -# heuristic touch them — a single LF/CRLF substitution inside a compressed stream or an OLE sector -# corrupts the file, and the parsers would then be tested against garbage that git created. -*.xlsx binary -*.xlsm binary -*.xlsb binary -*.xls binary - -# The benchmark CSV fixture is deliberately left under the rule above rather than marked -text: -# its blob is already LF, and -text would freeze whatever a contributor's working tree happens to -# hold, which on a machine with core.autocrlf=true means silently rewriting it to CRLF. Tests that -# actually cover terminator handling build their own fixtures in code. diff --git a/.github/ISSUE_TEMPLATE/bug_report.md b/.github/ISSUE_TEMPLATE/bug_report.md new file mode 100644 index 0000000..9051eb1 --- /dev/null +++ b/.github/ISSUE_TEMPLATE/bug_report.md @@ -0,0 +1,38 @@ +--- +name: Bug report +about: Something isn't working as expected +title: "" +labels: bug +--- + +**Describe the bug** +A clear description of what's wrong: stale data after a write, a result that should have been +cached and wasn't (or the reverse), an exception, etc. + +**Package(s) and cache involved** +QueryCache.EFCore / QueryCache.Dapper / QueryCache.Core — in-process, or which `HybridCache` +(Microsoft, FusionCache...) over which distributed cache. + +**Reproduction** +Minimal code sample: the query, how it is cached, and the write or call sequence that shows the +problem. Mention transactions (`BeginTransaction`, `TransactionScope`) if any are involved. + +```csharp +// minimal repro here +``` + +**Expected behavior** +What you expected to happen. + +**Actual behavior** +What actually happened — include the full exception message/stack trace if there is one. + +**Environment** +- QueryCache version: +- Database and provider (e.g. SQL Server + Microsoft.EntityFrameworkCore.SqlServer 10.0.3): +- .NET version: +- OS: + +**Note on security issues:** if this bug could expose one caller's data to another, or put secrets +in the cache, please do **not** open a public issue — see [SECURITY.md](../../SECURITY.md) for the +private reporting channel instead. diff --git a/.github/ISSUE_TEMPLATE/feature_request.md b/.github/ISSUE_TEMPLATE/feature_request.md new file mode 100644 index 0000000..2227a5a --- /dev/null +++ b/.github/ISSUE_TEMPLATE/feature_request.md @@ -0,0 +1,22 @@ +--- +name: Feature request +about: Suggest an addition or change to the library +title: "" +labels: enhancement +--- + +**What problem does this solve?** +Describe the use case — what are you trying to do that the library doesn't support today? + +**Proposed API/behavior** +Sketch the API shape you'd expect, if you have one in mind. + +```csharp +// proposed usage +``` + +**Alternatives considered** +Any workarounds you're using today, or other approaches you considered. + +**Additional context** +Anything else — links, related issues, prior art in other libraries. diff --git a/.mailmap b/.mailmap new file mode 100644 index 0000000..9d77a75 --- /dev/null +++ b/.mailmap @@ -0,0 +1,4 @@ +Gabriel Matte +Gabriel Matte +Gabriel Matte +Gabriel Matte <61604367+GabrielMarquezMatte@users.noreply.github.com> diff --git a/CODE_OF_CONDUCT.md b/CODE_OF_CONDUCT.md new file mode 100644 index 0000000..aa928b4 --- /dev/null +++ b/CODE_OF_CONDUCT.md @@ -0,0 +1,48 @@ +# Code of Conduct + +## Our Pledge + +We as members, contributors, and leaders pledge to make participation in our community a +harassment-free experience for everyone, regardless of age, body size, visible or invisible +disability, ethnicity, sex characteristics, gender identity and expression, level of experience, +education, socio-economic status, nationality, personal appearance, race, religion, or sexual +identity and orientation. + +## Our Standards + +Examples of behavior that contributes to a positive environment: + +- Demonstrating empathy and kindness toward other people +- Being respectful of differing opinions, viewpoints, and experiences +- Giving and gracefully accepting constructive feedback +- Accepting responsibility and apologizing for mistakes, and learning from the experience + +Examples of unacceptable behavior: + +- The use of sexualized language or imagery, and sexual attention or advances of any kind +- Trolling, insulting or derogatory comments, and personal or political attacks +- Public or private harassment +- Publishing others' private information without explicit permission +- Other conduct which could reasonably be considered inappropriate in a professional setting + +## Enforcement Responsibilities + +Maintainers are responsible for clarifying and enforcing these standards, and will take appropriate +and fair corrective action in response to any behavior deemed inappropriate, threatening, offensive, +or harmful. + +## Scope + +This Code of Conduct applies within all project spaces (issues, pull requests, discussions) and when +an individual is officially representing the project in public spaces. + +## Enforcement + +Instances of abusive, harassing, or otherwise unacceptable behavior may be reported to the +maintainers via GitHub's private reporting channel on this repository. All complaints will be +reviewed and investigated promptly and fairly. + +## Attribution + +This Code of Conduct is adapted from the [Contributor Covenant](https://www.contributor-covenant.org), +version 2.1. diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md new file mode 100644 index 0000000..e494612 --- /dev/null +++ b/CONTRIBUTING.md @@ -0,0 +1,66 @@ +# Contributing + +Thanks for considering a contribution. This project takes small, focused pull requests over large +rewrites. The [README](README.md) describes what the cache guarantees (key, transactions, invalidation, +empty results); a change that weakens one of those guarantees needs to say so explicitly. + +## Build expectations + +- **Warnings are errors.** `Directory.Build.props` sets `TreatWarningsAsErrors`, with a curated + `AnalysisMode=All` analyzer set (NetAnalyzers plus Meziantou). A PR that doesn't build clean + locally won't build clean in CI either — run a full build before pushing: + + ```bash + dotnet build QueryCache.slnx --configuration Release + ``` + +- **Public API changes require a `PublicAPI.Unshipped.txt` entry.** `Microsoft.CodeAnalysis.PublicApiAnalyzers` + is active and fails the build on any unrecorded public member. If you add, change, or remove + anything public, update `src//PublicAPI/PublicAPI.Unshipped.txt` + (`python3 .github/scripts/add_missing_public_api.py` does it for you). A bot promotes + `Unshipped` → `Shipped` automatically after each release — don't edit `Shipped.txt` by hand. + +- **Tests are required for behavior changes.** Run the unit suite before opening a PR: + + ```bash + dotnet test --project tests/QueryCache.Tests/QueryCache.Tests.csproj --configuration Release + ``` + + Changes to keys, invalidation, transactions or the `HybridCache` path also need the integration + suite, which runs SQL Server, PostgreSQL and Redis through Testcontainers (Docker required): + + ```bash + dotnet test --project tests/QueryCache.IntegrationTests/QueryCache.IntegrationTests.csproj --configuration Release + ``` + + A cache bug usually shows up as a *wrong* answer rather than a crash, so a test should assert + the data the caller gets back (or how many times the database was queried), not just that no + exception was thrown. + +- **Benchmarks** live in `benchmarks/QueryCache.Benchmarks`. A new benchmark class needs a group in + `benchmark-groups.json`, or CI fails. A PR claiming a performance change should include + before/after numbers. + +## Commit messages + +Use [Conventional Commits](https://www.conventionalcommits.org/): `type(scope): summary`, imperative +mood, lowercase summary, no trailing period. Common types: `feat`, `fix`, `refactor`, `perf`, `test`, +`docs`, `chore`, `ci`, `build`. The scope is usually the package or area touched (`core`, `efcore`, +`dapper`, `hybrid`). Example: `fix(efcore): invalidate again when an ambient transaction commits`. + +## Pull requests + +- Open pull requests against `develop`; `master` receives releases. +- One focused change per PR — don't batch unrelated fixes into one commit or one PR. +- If a change is user-visible (new API, behavior change, performance claim), mention it in the PR + description; release notes are written separately, not as part of every PR. +- CI runs on Linux, Windows, and macOS — a change that only builds on one OS isn't ready to merge. + +## Reporting bugs / requesting features + +Use GitHub Issues for bugs and feature requests. For suspected security vulnerabilities, do **not** +open a public issue — see [SECURITY.md](SECURITY.md) for the private reporting channel. + +## Code of conduct + +This project follows the [Code of Conduct](CODE_OF_CONDUCT.md). diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..bc93381 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,23 @@ +# Security Policy + +## Supported Versions + +Only the latest published release of the `QueryCache.*` packages receives security fixes. Older +releases are not patched retroactively; upgrade to the latest version before reporting an issue. + +## Reporting a Vulnerability + +Please **do not** open a public GitHub issue for security vulnerabilities. + +Report vulnerabilities privately via +[GitHub Private Vulnerability Reporting](https://github.com/GabrielMarquezMatte/QueryCache/security/advisories/new). + +Include, where possible: +- The package(s) involved (`QueryCache.Core`, `QueryCache.EFCore`, `QueryCache.Dapper`) and the cache + in use (in-process, or which `HybridCache` implementation) +- A minimal code sample that reproduces it +- The impact you observed (one caller or tenant seeing another's data, stale data after a write, + secrets reaching the cache, excessive memory/CPU, etc.) + +You should receive an initial response within 5 business days. If the report is confirmed, a fix +will be prepared and released before any public disclosure.