Skip to content

ci: make nuget.org publish dispatch-only and block 3.10.x - #274

Merged
sfmskywalker merged 2 commits into
mainfrom
cursor/packages-nuget-dispatch-only-8148
Oct 3, 2026
Merged

sfmskywalker merged 2 commits into
mainfrom
cursor/packages-nuget-dispatch-only-8148

Conversation

@sfmskywalker

@sfmskywalker sfmskywalker commented Oct 3, 2026 •

Copy link
Copy Markdown
Member

Stop 3.10.x packages from reaching nuget.org. The publish_nuget job no longer runs on release or push; it is workflow_dispatch-only and requires an explicit publish_nuget input (default false) plus a computed version that does not start with 3.10..

There is no npm / npmjs.org publish in this workflow (or in any workflow it calls — packages.yml is self-contained). Feedz preview publish on push is unchanged.

Same shape as elsa-studio#1117: dispatch-only, input defaults to false, !startsWith(needs.build.outputs.version, '3.10.'), the build job exports the version, Feedz unchanged.

What changed

  • Added workflow_dispatch input publish_nuget (boolean, default false).
  • Exposed the version the build job already computes as needs.build.outputs.version.
  • publish_nuget if: is now dispatch + inputs.publish_nuget + !startsWith(needs.build.outputs.version, '3.10.').
  • Artifact upload also runs on workflow_dispatch so a future non-3.10.x dispatch can actually push if both gates pass.
  • publish_preview_feedz if: is unchanged (release or push).
  • YAML comments next to the new input and the guarded nuget.org job (Code Review note from studio#1117): these inputs do nothing on main while base_version is 3.10.x. Publishing 3.10 publicly later means deliberately removing the 3.10. check and deciding how a dispatch run sets VERSION (today always base_version-prefix.run_number).

On current main (base_version: 3.10.0), every computed version starts with 3.10. (preview builds are 3.10.0-preview.<run>). Dispatch from a 3.10.x tag also computes a 3.10.0-… version because tag-as-version only applies to release events. Both paths are blocked.

Publish job matrix

Job New if: (a) push to main (b) release published (c) dispatch on main (d) dispatch from a 3.10.x tag
publish_preview_feedz github.event_name == 'release' || github.event_name == 'push' yes yes no no
publish_nuget github.event_name == 'workflow_dispatch' && inputs.publish_nuget && !startsWith(needs.build.outputs.version, '3.10.') no no no (version is 3.10.0-preview.<run>, even if publish_nuget=true) no (computed version still starts with 3.10.)

No npmjs.org publish job exists.

Validation

actionlint v1.7.12 on .github/workflows/packages.yml: clean. Not merged, tagged, published, or dispatched.

Open in Web Open in Cursor 

Stop release-published events from pushing 3.10.x to nuget.org. The
nuget.org job now requires workflow_dispatch with publish_nuget=true
and a computed version that does not start with 3.10. Feedz preview
publish on push is unchanged. No npm publish exists in this workflow.

Co-authored-by: Sipke Schoorstra <sipkeschoorstra@outlook.com>
@cursor

cursor Bot commented Oct 3, 2026

Copy link
Copy Markdown

@greptileai

Add the Code Review note from elsa-studio#1117 next to the dispatch
input and the guarded nuget.org job: those inputs do nothing on main
while base_version is 3.10.x, because dispatch VERSION is always
base_version-prefix.run_number. Publishing 3.10 publicly later means
deliberately removing the 3.10. check and deciding how dispatch sets
the version. Gates and Feedz are unchanged.

Co-authored-by: Sipke Schoorstra <sipkeschoorstra@outlook.com>

@sfmskywalker sfmskywalker left a comment

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Elsa 3 Code Review: APPROVE + HIGH @ 7bfefe5

Code Review, Round 1/4

This PR is the elsa-extensions twin of elsa-studio#1117: a publish guard for 3.10 on main. It changes only .github/workflows/packages.yml.

What I checked

  • nuget.org: publish_nuget no longer runs when a release is published. It now needs all three of these:
    • a workflow_dispatch run;
    • inputs.publish_nuget set (it defaults to false);
    • a version that doesn't start with 3.10..
  • Version output: Set VERSION variable now has id: set_version and writes version to $GITHUB_OUTPUT on both the tag branch and the preview branch. The build job exposes it as needs.build.outputs.version, and VERSION in $GITHUB_ENV is unchanged for later steps.
  • Fails closed: a dispatch run always takes the preview branch, because the tag branch needs a release event, and base_version is '3.10.0'. So on main the gate can't open whatever inputs are set. The new comments on the input and on the job say exactly this, and say what lifting it would take.
  • Artifact upload: it now also runs on workflow_dispatch, so a legitimate future dispatch publish has packages to download. Dispatch on main only uploads a workflow artifact, with no extra publish. publish_preview_feedz is still limited to push and release, so a dispatch can't publish to Feedz.
  • 3.9 unaffected: published releases run the workflow file at the tag's commit, and release/3.9.0 is untouched.

Gate

  • Greptile is waived for elsa-extensions.
  • GitGuardian and CLA are green. ubuntu-latest, submit-nuget and CodeQL were still running when I posted this.
  • This approval holds only for this head. Merge once ubuntu-latest is green, and don't push again before merging.

@sfmskywalker
sfmskywalker marked this pull request as ready for review October 3, 2026 21:02
@sfmskywalker
sfmskywalker merged commit c638939 into main Oct 3, 2026
8 checks passed
@sfmskywalker
sfmskywalker deleted the cursor/packages-nuget-dispatch-only-8148 branch October 3, 2026 21:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants