Skip to content

ci: fail fast when the NuGet API key is empty - #276

Merged
sfmskywalker merged 1 commit into
mainfrom
ci/nuget-empty-key-guard
Oct 4, 2026
Merged

sfmskywalker merged 1 commit into
mainfrom
ci/nuget-empty-key-guard

Conversation

@sfmskywalker

Copy link
Copy Markdown
Member

Part of elsa-workflows/elsa-core#8600. Adds a Check API key step right before the feedz.io push and the nuget.org push.

If the key is empty (an unset secret or a missing login step output), the job now stops before any push with a clear ::error:: that names the feed, instead of every package failing with a 401. The key is only tested for emptiness; it's never printed. Nothing else changes about the push.

@sfmskywalker sfmskywalker left a comment

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Elsa 3 Code Review: APPROVE + HIGH @ 22c37a0

Code Review, Round 1/4

Scope: .github/workflows/packages.yml, +18 lines. Adds two steps: Check API key (feedz.io) before Publish to feedz.io, and Check API key (nuget.org) between NuGet login and Publish to nuget.org. Tracks elsa-core#8600.

Verdict: No blockers. The change matches elsa-studio#1120: same steps, same behaviour.

Checks

  • (a) Key handling. Both guards take the key through env: API_KEY and test it with [ -z "$API_KEY" ]. There is no ${{ }} in the script, no echo of the key and no set -x.
  • (b) Same source as the push.
    • feedz.io: secrets.FEEDZ_API_KEY, the same as Publish to feedz.io.
    • nuget.org: steps.nuget_login.outputs.NUGET_API_KEY, the same OIDC output Publish to nuget.org uses. The workflow does not read secrets.NUGET_API_KEY.
  • (c) Conditions. The push steps have no step-level if:, so the guards share their push step's job-level if: exactly:
    • publish_preview_feedz: release || push.
    • publish_nuget: dispatch + inputs.publish_nuget + !startsWith(needs.build.outputs.version, '3.10.'). On main that gate never opens while base_version is 3.10.0, so the nuget.org guard cannot fire there either.
  • (e) Error and exit. Each ::error:: names its feed and is followed by exit 1. Run locally, an empty key exits 1 and a set key exits 0.
  • (f) Lint. The YAML parses. actionlint 1.7.7 with shellcheck reports nothing on the new steps. Its only findings are shellcheck info/warnings in the existing build scripts and the existing *.nupkg globs (SC2035).
  • (h) Duplication. Copying the steps from elsa-studio is acceptable for two trivial steps in separate repositories.

Non-blocking

  • N1. The feedz.io error points at OIDC. As on elsa-studio#1120, the feedz.io message says "Check the secret or the NuGet login (OIDC) step output". That job has no login step. Suggested text: API key for feedz.io is empty. Check the FEEDZ_API_KEY secret; nothing was pushed. Keep the wording the same as studio.
  • N2. The push commands still put the key straight into the command line (pre-existing). They interpolate it with -k ${{ … }}. Optionally, read "$API_KEY" from env: in the push step and put the guard there too.

Bots and CI on 22c37a09

  • ubuntu-latest, submit-nuget, CodeQL (all Analyze jobs), GitGuardian and CLA passed.
  • Greptile is waived for this repository and did not run. CodeRabbit, Copilot and Bugbot did not review either.
  • No threads. Merge state is CLEAN.

Gate: APPROVE + HIGH and green CI on 22c37a09.

@sfmskywalker
sfmskywalker merged commit 6d76404 into main Oct 4, 2026
9 checks passed
@sfmskywalker
sfmskywalker deleted the ci/nuget-empty-key-guard branch October 4, 2026 02:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant