Repository navigation
ci: fail fast when the NuGet API key is empty - #276
Merged
Merged
Conversation
sfmskywalker
commented
Oct 4, 2026
sfmskywalker
left a comment
Member
Author
There was a problem hiding this comment.
Elsa 3 Code Review: APPROVE + HIGH @ 22c37a0
Code Review, Round 1/4
Scope: .github/workflows/packages.yml, +18 lines. Adds two steps: Check API key (feedz.io) before Publish to feedz.io, and Check API key (nuget.org) between NuGet login and Publish to nuget.org. Tracks elsa-core#8600.
Verdict: No blockers. The change matches elsa-studio#1120: same steps, same behaviour.
Checks
- (a) Key handling. Both guards take the key through
env: API_KEYand test it with[ -z "$API_KEY" ]. There is no${{ }}in the script, no echo of the key and noset -x. - (b) Same source as the push.
- feedz.io:
secrets.FEEDZ_API_KEY, the same asPublish to feedz.io. - nuget.org:
steps.nuget_login.outputs.NUGET_API_KEY, the same OIDC outputPublish to nuget.orguses. The workflow does not readsecrets.NUGET_API_KEY.
- feedz.io:
- (c) Conditions. The push steps have no step-level
if:, so the guards share their push step's job-levelif:exactly:publish_preview_feedz:release || push.publish_nuget: dispatch +inputs.publish_nuget+!startsWith(needs.build.outputs.version, '3.10.'). Onmainthat gate never opens whilebase_versionis 3.10.0, so the nuget.org guard cannot fire there either.
- (e) Error and exit. Each
::error::names its feed and is followed byexit 1. Run locally, an empty key exits 1 and a set key exits 0. - (f) Lint. The YAML parses.
actionlint1.7.7 with shellcheck reports nothing on the new steps. Its only findings are shellcheck info/warnings in the existing build scripts and the existing*.nupkgglobs (SC2035). - (h) Duplication. Copying the steps from elsa-studio is acceptable for two trivial steps in separate repositories.
Non-blocking
- N1. The feedz.io error points at OIDC. As on elsa-studio#1120, the feedz.io message says "Check the secret or the NuGet login (OIDC) step output". That job has no login step. Suggested text:
API key for feedz.io is empty. Check the FEEDZ_API_KEY secret; nothing was pushed.Keep the wording the same as studio. - N2. The push commands still put the key straight into the command line (pre-existing). They interpolate it with
-k ${{ … }}. Optionally, read"$API_KEY"fromenv:in the push step and put the guard there too.
Bots and CI on 22c37a09
ubuntu-latest,submit-nuget, CodeQL (all Analyze jobs), GitGuardian and CLA passed.- Greptile is waived for this repository and did not run. CodeRabbit, Copilot and Bugbot did not review either.
- No threads. Merge state is CLEAN.
Gate: APPROVE + HIGH and green CI on 22c37a09.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part of elsa-workflows/elsa-core#8600. Adds a
Check API keystep right before the feedz.io push and the nuget.org push.If the key is empty (an unset secret or a missing login step output), the job now stops before any push with a clear
::error::that names the feed, instead of every package failing with a 401. The key is only tested for emptiness; it's never printed. Nothing else changes about the push.