Skip to content

Move CI and release to the DragoAnt reusable workflow with Trusted Publishing - #1

Merged
vfofanov merged 2 commits into
mainfrom
feat/workflows
Oct 3, 2026
Merged

vfofanov merged 2 commits into
mainfrom
feat/workflows

Conversation

@vfofanov

@vfofanov vfofanov commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Replaces build.yml + build_and_publish_nuget.yml with thin callers of the reusable dotnet-build workflow.

  • ci.yml — push to main, pull requests, manual runs; cancels superseded PR runs. Test table + coverage summary in the job summary, 70 % line-coverage floor (77 % today, test assemblies excluded), test results and coverage as artifacts. Runs dotnet at the repo root, so the .sln → .slnx switch needs no change here.
  • release.yml — on release: published: version from the tag (leading v stripped, SemVer checked, -suffix ⇔ GitHub pre-release flag, 9999.* refused) → build/test/pack once with contents: read only → publish job in environment nuget logs in with nuget.org Trusted Publishing (NuGet/login, id-token: write) and pushes *.nupkg (+ .snupkg) with --skip-duplicate. If the Trusted Publishing login fails it falls back to the NUGET_ORG_API_KEY secret with a warning; with neither it fails with a setup message.
  • dependabot.yml — actions, NuGet (grouped, weekly; Verify held at ≤ 32.0.0, FluentAssertions and Microsoft.Extensions.* majors ignored) and the .msbuild submodule.

All actions pinned to full SHAs (node24); actionlint clean.

⚠️ Before merging

  • Merge Add org profile, community health defaults and reusable .NET workflows .github#1 first, then re-point the uses: line in ci.yml and release.yml from 6c9ee08… (its PR head) to the merged main SHA.
  • Settings → Environments → New environment nuget: required reviewer (yourself), deployment tags rule v*.
  • nuget.org → Trusted Publishing → Add policy: owner DragoAnt, repository Extensions.System.Text.Json, workflow file release.yml, environment nuget. Set a NUGET_USER repo variable only if the nuget.org account owning the policy is not DragoAnt. Once a release has published through it, the NUGET_ORG_API_KEY secret can go.
  • Settings → Code security → Private vulnerability reporting: enable (SECURITY.md points to it).
  • Update CONTRIBUTING.md ("The build workflow must pass") and the README build badge (build.yml → ci.yml) — left alone here to keep this PR to .github/.
Release version step — dry run
Tag Pre-release flag Result
v2.0.0 false ✅ 2.0.0
2.0.0 false ✅ 2.0.0
v2.1.0-beta.1 true ✅ 2.1.0-beta.1
v2.1.0-beta.1 false ❌ pre-release version, tick Set as a pre-release
v2.0.0 true ❌ marked pre-release but no -suffix
v2.0 false ❌ not SemVer
v9999.0.0 false ❌ local development version
v2.0.0+build.5 false ❌ build metadata refused

dotnet pack -p:Version=2.1.0-beta.1 with GITHUB_REF_TYPE=tag produced DragoAnt.System.Text.Json.Observer{,.Http}.2.1.0-beta.1.{nupkg,snupkg}.

- ci: push to main, pull requests and manual runs; test table,
  coverage summary and artifacts from the reusable dotnet-build
  workflow
- release: version from the release tag (leading v stripped, SemVer
  and pre-release flag checked), build/test/pack once without
  credentials, publish in the nuget environment with nuget.org
  Trusted Publishing
- dependabot: actions, NuGet (grouped, weekly), .msbuild submodule
@vfofanov
vfofanov merged commit 81c24cd into main Oct 3, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant