Repository navigation
Move CI and release to the DragoAnt reusable workflow with Trusted Publishing - #1
Merged
Merged
Conversation
- ci: push to main, pull requests and manual runs; test table, coverage summary and artifacts from the reusable dotnet-build workflow - release: version from the release tag (leading v stripped, SemVer and pre-release flag checked), build/test/pack once without credentials, publish in the nuget environment with nuget.org Trusted Publishing - dependabot: actions, NuGet (grouped, weekly), .msbuild submodule
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Replaces
build.yml+build_and_publish_nuget.ymlwith thin callers of the reusabledotnet-buildworkflow.ci.yml— push tomain, pull requests, manual runs; cancels superseded PR runs. Test table + coverage summary in the job summary, 70 % line-coverage floor (77 % today, test assemblies excluded), test results and coverage as artifacts. Runsdotnetat the repo root, so the.sln→.slnxswitch needs no change here.release.yml— onrelease: published: version from the tag (leadingvstripped, SemVer checked,-suffix⇔ GitHub pre-release flag,9999.*refused) → build/test/pack once withcontents: readonly →publishjob in environmentnugetlogs in with nuget.org Trusted Publishing (NuGet/login,id-token: write) and pushes*.nupkg(+.snupkg) with--skip-duplicate. If the Trusted Publishing login fails it falls back to theNUGET_ORG_API_KEYsecret with a warning; with neither it fails with a setup message.dependabot.yml— actions, NuGet (grouped, weekly;Verifyheld at ≤ 32.0.0,FluentAssertionsandMicrosoft.Extensions.*majors ignored) and the.msbuildsubmodule.All actions pinned to full SHAs (
node24);actionlintclean.uses:line inci.ymlandrelease.ymlfrom6c9ee08…(its PR head) to the mergedmainSHA.nuget: required reviewer (yourself), deployment tags rulev*.DragoAnt, repositoryExtensions.System.Text.Json, workflow filerelease.yml, environmentnuget. Set aNUGET_USERrepo variable only if the nuget.org account owning the policy is notDragoAnt. Once a release has published through it, theNUGET_ORG_API_KEYsecret can go.SECURITY.mdpoints to it).CONTRIBUTING.md("Thebuildworkflow must pass") and the README build badge (build.yml→ci.yml) — left alone here to keep this PR to.github/.Release version step — dry run
v2.0.02.0.02.0.02.0.0v2.1.0-beta.12.1.0-beta.1v2.1.0-beta.1v2.0.0-suffixv2.0v9999.0.0v2.0.0+build.5dotnet pack -p:Version=2.1.0-beta.1withGITHUB_REF_TYPE=tagproducedDragoAnt.System.Text.Json.Observer{,.Http}.2.1.0-beta.1.{nupkg,snupkg}.