From 201d7b235893b0da39fd83fee228d9eafd6b61e6 Mon Sep 17 00:00:00 2001 From: Cursor Agent Date: Sat, 3 Oct 2026 20:47:35 +0000 Subject: [PATCH 1/2] ci: make nuget.org publish dispatch-only and block 3.10.x Stop release-published events from pushing 3.10.x to nuget.org. The nuget.org job now requires workflow_dispatch with publish_nuget=true and a computed version that does not start with 3.10. Feedz preview publish on push is unchanged. No npm publish exists in this workflow. Co-authored-by: Sipke Schoorstra --- .github/workflows/packages.yml | 17 ++++++++++++++--- 1 file changed, 14 insertions(+), 3 deletions(-) diff --git a/.github/workflows/packages.yml b/.github/workflows/packages.yml index a34ed96b..eabe02be 100644 --- a/.github/workflows/packages.yml +++ b/.github/workflows/packages.yml @@ -1,6 +1,11 @@ name: Packages on: workflow_dispatch: + inputs: + publish_nuget: + description: 'Publish packages to nuget.org (never for 3.10.x)' + type: boolean + default: false push: branches: - 'main' @@ -26,6 +31,8 @@ jobs: name: Build packages runs-on: ubuntu-latest timeout-minutes: 30 + outputs: + version: ${{ steps.set_version.outputs.version }} steps: - name: Extract branch name run: | @@ -56,13 +63,17 @@ jobs: git branch --remote --contains | grep origin/${BRANCH_NAME} fi - name: Set VERSION variable + id: set_version run: | if [[ "${{ github.ref }}" == refs/tags/* && "${{ github.event_name }}" == "release" && ("${{ github.event.action }}" == "published" || "${{ github.event.action }}" == "prereleased") ]]; then TAG_NAME=${{ github.ref }} # e.g., refs/tags/3.0.0 TAG_NAME=${TAG_NAME#refs/tags/} # remove the refs/tags/ prefix echo "VERSION=${TAG_NAME}" >> $GITHUB_ENV + echo "version=${TAG_NAME}" >> $GITHUB_OUTPUT else - echo "VERSION=${{env.base_version}}-${PACKAGE_PREFIX}.${{github.run_number}}" >> $GITHUB_ENV + VERSION="${{env.base_version}}-${PACKAGE_PREFIX}.${{github.run_number}}" + echo "VERSION=${VERSION}" >> $GITHUB_ENV + echo "version=${VERSION}" >> $GITHUB_OUTPUT fi - uses: actions/setup-dotnet@v5 with: @@ -77,7 +88,7 @@ jobs: with: name: elsa-nuget-packages path: packages/*nupkg - if: ${{ github.event_name == 'release' || github.event_name == 'push'}} + if: ${{ github.event_name == 'release' || github.event_name == 'push' || github.event_name == 'workflow_dispatch'}} publish_preview_feedz: name: Publish to feedz.io @@ -99,7 +110,7 @@ jobs: needs: build runs-on: ubuntu-latest timeout-minutes: 20 - if: ${{ github.event_name == 'release' && github.event.action == 'published' }} + if: ${{ github.event_name == 'workflow_dispatch' && inputs.publish_nuget && !startsWith(needs.build.outputs.version, '3.10.') }} permissions: # Required to request the OIDC token that nuget.org exchanges for a short-lived API key (Trusted Publishing). id-token: write From 7bfefe5005c800973ccb2b23ca5f14f214b16507 Mon Sep 17 00:00:00 2001 From: Cursor Agent Date: Sat, 3 Oct 2026 20:50:45 +0000 Subject: [PATCH 2/2] ci: document that publish_nuget is inert on 3.10.x main Add the Code Review note from elsa-studio#1117 next to the dispatch input and the guarded nuget.org job: those inputs do nothing on main while base_version is 3.10.x, because dispatch VERSION is always base_version-prefix.run_number. Publishing 3.10 publicly later means deliberately removing the 3.10. check and deciding how dispatch sets the version. Gates and Feedz are unchanged. Co-authored-by: Sipke Schoorstra --- .github/workflows/packages.yml | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/.github/workflows/packages.yml b/.github/workflows/packages.yml index eabe02be..5eb70e05 100644 --- a/.github/workflows/packages.yml +++ b/.github/workflows/packages.yml @@ -2,6 +2,11 @@ name: Packages on: workflow_dispatch: inputs: + # Does nothing on main while base_version is 3.10.x. Dispatch VERSION is + # always ${base_version}-${prefix}.${run_number}, so the nuget.org job's + # !startsWith(..., '3.10.') gate never opens. Publishing 3.10 publicly + # later means deliberately removing that check and deciding how a dispatch + # run sets VERSION. publish_nuget: description: 'Publish packages to nuget.org (never for 3.10.x)' type: boolean @@ -110,6 +115,10 @@ jobs: needs: build runs-on: ubuntu-latest timeout-minutes: 20 + # Dispatch-only. 3.10.x (including 3.10.0-preview.*) must never reach nuget.org. + # publish_nuget does nothing on main while base_version is 3.10.x. Publishing + # 3.10 publicly later means deliberately removing the 3.10. check and deciding + # how a dispatch run sets VERSION (always base_version-prefix.run_number). if: ${{ github.event_name == 'workflow_dispatch' && inputs.publish_nuget && !startsWith(needs.build.outputs.version, '3.10.') }} permissions: # Required to request the OIDC token that nuget.org exchanges for a short-lived API key (Trusted Publishing).