Skip to content

ci: feedz.io empty-key wording + pass push keys via env (#8600 follow-up) - #277

Merged
sfmskywalker merged 1 commit into
mainfrom
fix/8600-feedz-wording-env-key
Oct 4, 2026
Merged

sfmskywalker merged 1 commit into
mainfrom
fix/8600-feedz-wording-env-key

Conversation

@sfmskywalker

Copy link
Copy Markdown
Member

Follow-up to elsa-workflows/elsa-core#8600 (Code Review non-blocking items on the empty-key guard PR).

  • N1: the feedz.io empty-key error now names the FEEDZ_API_KEY repository secret only. That job never uses the NuGet login (OIDC) step. The nuget.org error now points at the OIDC login output and the Trusted Publishing policy.
  • N2: both dotnet nuget push steps take the key from a step-level env: API_KEY and use "$API_KEY", instead of interpolating ${{ }} into the command line.

No behaviour change otherwise. Each check still reads exactly what its push uses, and the conditions are unchanged.

@sfmskywalker sfmskywalker left a comment

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Elsa 3 Code Review: APPROVE + HIGH @ 2addf54

Code Review, Round 1/4

Scope: .github/workflows/packages.yml +8/-4. Fixes N1 and N2 from #276 (elsa-core#8600 follow-up).

Verdict: No blockers.

Checks

  • Same source as before.
    • Publish to feedz.io now has env: API_KEY: ${{ secrets.FEEDZ_API_KEY }}, as before, and it matches its guard.
    • Publish to nuget.org now has env: API_KEY: ${{ steps.nuget_login.outputs.NUGET_API_KEY }}, the same OIDC output as before and as its guard.
  • Quoting and exposure.
    • The key is passed as -k "$API_KEY", double-quoted.
    • No ${{ }} key expression is left on a command line.
    • Nothing echoes the key, and there is no set -x.
  • Conditions. The if: lines are identical to the base, including !startsWith(needs.build.outputs.version, '3.10.') on publish_nuget.
  • Messages. The wording is the same as elsa-studio#1121: feedz.io names FEEDZ_API_KEY, and nuget.org names the OIDC login output and the Trusted Publishing policy. Each is followed by exit 1.
  • actionlint. 1.7.7 with shellcheck reports 13 findings on both base and head, and none are new.
  • Consistency with elsa-studio#1121. The guards, the env: blocks and the quoting match. Only pre-existing details differ: the glob path and the flag spelling.

Non-blocking

  • N1. "repository secret" is not accurate here. The feedz.io message says "Check the FEEDZ_API_KEY repository secret". For elsa-extensions, FEEDZ_API_KEY exists only at organization level. Suggested wording: "the FEEDZ_API_KEY secret (repository or organization)". Keep it the same as studio.

Bots and CI on 2addf548

  • CI: all green: ubuntu-latest, submit-nuget, CodeQL (all Analyze jobs), GitGuardian and CLA. Merge state is CLEAN.
  • Greptile: waived for this repository. It did not run.
  • CodeRabbit, Copilot and Bugbot: did not review.
  • Threads: none.

Gate: APPROVE + HIGH and green CI on 2addf548. Met.

@sfmskywalker
sfmskywalker merged commit caaae98 into main Oct 4, 2026
8 checks passed
@sfmskywalker
sfmskywalker deleted the fix/8600-feedz-wording-env-key branch October 4, 2026 03:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant