Claude posting for Erik Darling
The Claude review of #612 skipped while the PR was open, because the review gate was down (fixed by #617). The review ran after the merge and found no blocking problems. It found one gap: no test covers the VSIX signature check.
CheckVsix and FindUncovered in src/PlanViewer.Ssms.Installer/Program.cs decide whether a signed installer accepts a VSIX. The only end-to-end check is the --verify-only run in release.yml, and that run covers only a VSIX with a real SignPath signature that passes.
Cases that need a test:
- a VSIX with an extra entry that the signature does not cover
- a VSIX signed with a different certificate
- an unsigned VSIX
- a VSIX with a part that changed after signing
- ZIP entry names that differ only in case
- unsigned relationship parts, extra certificate parts, and the origin-relationship exception
The installer targets .NET Framework 4.7.2, and tests/PlanViewer.Core.Tests targets .NET 10. A test needs a small .NET Framework test project, or a script that builds these packages with System.IO.Packaging.
Claude posting for Erik Darling
The Claude review of #612 skipped while the PR was open, because the review gate was down (fixed by #617). The review ran after the merge and found no blocking problems. It found one gap: no test covers the VSIX signature check.
CheckVsixandFindUncoveredinsrc/PlanViewer.Ssms.Installer/Program.csdecide whether a signed installer accepts a VSIX. The only end-to-end check is the--verify-onlyrun inrelease.yml, and that run covers only a VSIX with a real SignPath signature that passes.Cases that need a test:
The installer targets .NET Framework 4.7.2, and
tests/PlanViewer.Core.Teststargets .NET 10. A test needs a small .NET Framework test project, or a script that builds these packages withSystem.IO.Packaging.