Repository navigation
ci: make nuget.org publish dispatch-only and block 3.10.x - #274
Merged
Merged
Conversation
Stop release-published events from pushing 3.10.x to nuget.org. The nuget.org job now requires workflow_dispatch with publish_nuget=true and a computed version that does not start with 3.10. Feedz preview publish on push is unchanged. No npm publish exists in this workflow. Co-authored-by: Sipke Schoorstra <sipkeschoorstra@outlook.com>
Add the Code Review note from elsa-studio#1117 next to the dispatch input and the guarded nuget.org job: those inputs do nothing on main while base_version is 3.10.x, because dispatch VERSION is always base_version-prefix.run_number. Publishing 3.10 publicly later means deliberately removing the 3.10. check and deciding how dispatch sets the version. Gates and Feedz are unchanged. Co-authored-by: Sipke Schoorstra <sipkeschoorstra@outlook.com>
sfmskywalker
commented
Oct 3, 2026
sfmskywalker
left a comment
Member
Author
There was a problem hiding this comment.
Elsa 3 Code Review: APPROVE + HIGH @ 7bfefe5
Code Review, Round 1/4
This PR is the elsa-extensions twin of elsa-studio#1117: a publish guard for 3.10 on main. It changes only .github/workflows/packages.yml.
What I checked
- nuget.org:
publish_nugetno longer runs when a release is published. It now needs all three of these:- a
workflow_dispatchrun; inputs.publish_nugetset (it defaults tofalse);- a version that doesn't start with
3.10..
- a
- Version output:
Set VERSION variablenow hasid: set_versionand writesversionto$GITHUB_OUTPUTon both the tag branch and the preview branch. The build job exposes it asneeds.build.outputs.version, andVERSIONin$GITHUB_ENVis unchanged for later steps. - Fails closed: a dispatch run always takes the preview branch, because the tag branch needs a
releaseevent, andbase_versionis'3.10.0'. So onmainthe gate can't open whatever inputs are set. The new comments on the input and on the job say exactly this, and say what lifting it would take. - Artifact upload: it now also runs on
workflow_dispatch, so a legitimate future dispatch publish has packages to download. Dispatch onmainonly uploads a workflow artifact, with no extra publish.publish_preview_feedzis still limited topushandrelease, so a dispatch can't publish to Feedz. - 3.9 unaffected: published releases run the workflow file at the tag's commit, and
release/3.9.0is untouched.
Gate
- Greptile is waived for elsa-extensions.
- GitGuardian and CLA are green.
ubuntu-latest,submit-nugetand CodeQL were still running when I posted this. - This approval holds only for this head. Merge once
ubuntu-latestis green, and don't push again before merging.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stop 3.10.x packages from reaching nuget.org. The
publish_nugetjob no longer runs onreleaseorpush; it isworkflow_dispatch-only and requires an explicitpublish_nugetinput (defaultfalse) plus a computed version that does not start with3.10..There is no npm / npmjs.org publish in this workflow (or in any workflow it calls —
packages.ymlis self-contained). Feedz preview publish on push is unchanged.Same shape as elsa-studio#1117: dispatch-only, input defaults to false,
!startsWith(needs.build.outputs.version, '3.10.'), the build job exports the version, Feedz unchanged.What changed
workflow_dispatchinputpublish_nuget(boolean, defaultfalse).buildjob already computes asneeds.build.outputs.version.publish_nugetif:is now dispatch +inputs.publish_nuget+!startsWith(needs.build.outputs.version, '3.10.').workflow_dispatchso a future non-3.10.x dispatch can actually push if both gates pass.publish_preview_feedzif:is unchanged (releaseorpush).mainwhilebase_versionis 3.10.x. Publishing 3.10 publicly later means deliberately removing the3.10.check and deciding how a dispatch run setsVERSION(today alwaysbase_version-prefix.run_number).On current
main(base_version: 3.10.0), every computed version starts with3.10.(preview builds are3.10.0-preview.<run>). Dispatch from a3.10.xtag also computes a3.10.0-…version because tag-as-version only applies toreleaseevents. Both paths are blocked.Publish job matrix
if:publish_preview_feedzgithub.event_name == 'release' || github.event_name == 'push'publish_nugetgithub.event_name == 'workflow_dispatch' && inputs.publish_nuget && !startsWith(needs.build.outputs.version, '3.10.')3.10.0-preview.<run>, even ifpublish_nuget=true)3.10.)No npmjs.org publish job exists.
Validation
actionlintv1.7.12 on.github/workflows/packages.yml: clean. Not merged, tagged, published, or dispatched.