Repository navigation
ci: feedz.io empty-key wording + pass push keys via env (#8600 follow-up) - #277
Merged
Merged
Conversation
…a env (#8600 follow-up)
sfmskywalker
commented
Oct 4, 2026
sfmskywalker
left a comment
Member
Author
There was a problem hiding this comment.
Elsa 3 Code Review: APPROVE + HIGH @ 2addf54
Code Review, Round 1/4
Scope: .github/workflows/packages.yml +8/-4. Fixes N1 and N2 from #276 (elsa-core#8600 follow-up).
Verdict: No blockers.
Checks
- Same source as before.
Publish to feedz.ionow hasenv: API_KEY: ${{ secrets.FEEDZ_API_KEY }}, as before, and it matches its guard.Publish to nuget.orgnow hasenv: API_KEY: ${{ steps.nuget_login.outputs.NUGET_API_KEY }}, the same OIDC output as before and as its guard.
- Quoting and exposure.
- The key is passed as
-k "$API_KEY", double-quoted. - No
${{ }}key expression is left on a command line. - Nothing echoes the key, and there is no
set -x.
- The key is passed as
- Conditions. The
if:lines are identical to the base, including!startsWith(needs.build.outputs.version, '3.10.')onpublish_nuget. - Messages. The wording is the same as elsa-studio#1121: feedz.io names
FEEDZ_API_KEY, and nuget.org names the OIDC login output and the Trusted Publishing policy. Each is followed byexit 1. - actionlint. 1.7.7 with shellcheck reports 13 findings on both base and head, and none are new.
- Consistency with elsa-studio#1121. The guards, the
env:blocks and the quoting match. Only pre-existing details differ: the glob path and the flag spelling.
Non-blocking
- N1. "repository secret" is not accurate here. The feedz.io message says "Check the FEEDZ_API_KEY repository secret". For elsa-extensions,
FEEDZ_API_KEYexists only at organization level. Suggested wording: "the FEEDZ_API_KEY secret (repository or organization)". Keep it the same as studio.
Bots and CI on 2addf548
- CI: all green:
ubuntu-latest,submit-nuget, CodeQL (all Analyze jobs), GitGuardian and CLA. Merge state is CLEAN. - Greptile: waived for this repository. It did not run.
- CodeRabbit, Copilot and Bugbot: did not review.
- Threads: none.
Gate: APPROVE + HIGH and green CI on 2addf548. Met.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to elsa-workflows/elsa-core#8600 (Code Review non-blocking items on the empty-key guard PR).
FEEDZ_API_KEYrepository secret only. That job never uses the NuGet login (OIDC) step. The nuget.org error now points at the OIDC login output and the Trusted Publishing policy.dotnet nuget pushsteps take the key from a step-levelenv: API_KEYand use"$API_KEY", instead of interpolating${{ }}into the command line.No behaviour change otherwise. Each check still reads exactly what its push uses, and the conditions are unchanged.