Add a workflow to build and package the library - #5
Merged
Merged
Conversation
Produces the NuGet package as a CI artifact, and attaches it to a draft GitHub release when a v* tag is pushed. The package is proven to be the artifact that passed the tests: the solution is built once, tested, then packed with --no-build, so the assembly inside the .nupkg is byte for byte the one the test run exercised rather than a later rebuild. Versioning has two modes. A v* tag is authoritative and yields a release version; the step warns if the tag disagrees with the version declared in PkLibSharp.csproj, since that usually means the csproj was not bumped. Every other build yields a prerelease derived from the project version, the run number and the commit, so main builds and pull request builds produce uniquely identifiable packages. Packing sets ContinuousIntegrationBuild to normalise paths recorded in the PDB, and PublishRepositoryUrl with EmbedUntrackedSources so the accompanying .snupkg is usable for SourceLink debugging. A verification step asserts the things that are easy to lose silently: a package that builds is not necessarily one that is correct. It checks that both packages exist, that the nupkg carries LICENSE, README.md, the assembly and the XML documentation, that the nuspec declares the expected version, and that the snupkg carries the symbols. Restore runs in locked mode like the rest of CI, actions are pinned to commit SHAs, permissions are contents:read with the release job elevated to contents:write, and checkout runs with persist-credentials disabled. The release is created as a draft on purpose, so publishing stays a deliberate step. Pushing to NuGet.org is not wired up: it is an outward-facing action needing an API key secret this workflow neither has nor asks for. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds
.github/workflows/package.yml, which builds the NuGet package as a CI artifact and attaches it to a draft GitHub release when av*tag is pushed.The package is provably the tested build
The solution is built once, tested, then packed with
--no-build. The assembly inside the.nupkgis byte for byte the one the 966 tests exercised, not a later rebuild that merely used the same source.Versioning
v1.2.31.2.3main, PR, manual1.0.0-ci.<run>.g<sha>The tag is authoritative, but the step emits a
::warning::if it disagrees with the version inPkLibSharp.csproj— that mismatch almost always means the csproj wasn't bumped. Non-tag builds derive from the project version, so every main and PR build produces a uniquely identifiable package rather than overwriting1.0.0.Verification, because a package that builds isn't necessarily correct
A dedicated step asserts what's easy to lose silently:
.nupkgand.snupkgexistLICENSE,README.md,lib/net10.0/PkLibSharp.dll,lib/net10.0/PkLibSharp.xmllib/net10.0/PkLibSharp.pdbThe
LICENSEcheck matters specifically: the MIT terms require Zezula's notice to travel with the package, and that's an easy thing to break without noticing.Packing also sets
ContinuousIntegrationBuild(normalises PDB paths) plusPublishRepositoryUrlandEmbedUntrackedSources, so the symbol package is usable for SourceLink debugging. Confirmed the nuspec ends up with the full repository URL and commit rather than just a bare commit hash.Consistent with the existing security posture
--locked-moderestore, all four actions pinned to commit SHAs (each verified to exist upstream and carry the tag claimed in the comment),permissions: contents: readwith only the release job elevated tocontents: write,persist-credentials: falseon checkout, concurrency group, timeouts.Two deliberate stopping points
The release is a draft. Pushing a tag builds and attaches the package, but publishing stays a human step — consistent with the review gates already on this repo. Drop
--draftto publish automatically.NuGet.org publishing is not wired up. That's outward-facing and needs an API key secret this workflow neither has nor asks for. Happy to add it as a follow-up, ideally gated behind a GitHub Environment with a required reviewer.
Verification done before pushing
1.0.0-ci.42.g751d52aand2.5.0(with the warning firing correctly)build → test → pack --no-buildsequence run locally: 966 tests pass, both packages producedNo source or csproj changes — the packaging properties are passed on the command line, so local
dotnet packbehaviour is unchanged.