From 0ca4256081e4c0149229a2370f811437874e16c4 Mon Sep 17 00:00:00 2001 From: Ismael Leon Date: Mon, 21 Sep 2026 22:19:45 -0600 Subject: [PATCH] Release 3.0.0 and publish on version tags The 2.0.0 packages were already on the feed, so the #3 cleanup was never published: every push to main re-packed 2.0.0 and --skip-duplicate turned the 409 conflicts into a passing job. - Bump to 3.0.0; the #3 changes break the published 2.0.0 API. - Publish on vX.Y.Z tags and fail when the tag does not match the version in Directory.Build.props, which stays the single source of truth. - Drop --skip-duplicate so republishing an existing version fails loudly. - Skip symbol packages on push; GitHub Packages does not accept .snupkg. - Document the release steps in the README. Closes #6 --- .github/workflows/release.yml | 23 +++++++++++++++++++---- README.md | 10 +++++++++- src/Directory.Build.props | 4 ++-- 3 files changed, 30 insertions(+), 7 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index e372b78..a26113d 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -1,9 +1,10 @@ name: Release +# Publishing is explicit: push a tag matching the in +# src/Directory.Build.props (e.g. v3.0.0) after the bump is merged to main. on: push: - branches: [ "main" ] - workflow_dispatch: + tags: [ "v[0-9]+.[0-9]+.[0-9]+*" ] # Use the built-in GITHUB_TOKEN to publish to GitHub Packages — # no personal access token to manage or rotate. @@ -12,12 +13,15 @@ permissions: packages: write concurrency: - group: release-main + group: release cancel-in-progress: false jobs: publish: runs-on: ubuntu-latest + env: + # Keeps the first-run banner out of the version captured below. + DOTNET_NOLOGO: true steps: - name: Checkout @@ -28,6 +32,15 @@ jobs: with: dotnet-version: 8.0.x + - name: Check tag matches project version + run: | + project_version=$(dotnet msbuild src/Authorization.Abstractions -getProperty:Version) + tag_version="${GITHUB_REF_NAME#v}" + if [ "$project_version" != "$tag_version" ]; then + echo "::error::Tag $GITHUB_REF_NAME does not match project version $project_version" + exit 1 + fi + - name: Restore run: dotnet restore Authorization.sln @@ -48,9 +61,11 @@ jobs: retention-days: 7 path: ${{ github.workspace }}/artifacts/*.nupkg + # No --skip-duplicate: republishing an existing version must fail loudly. + # GitHub Packages does not accept .snupkg symbol packages. - name: Push to GitHub Packages run: > dotnet nuget push "${{ github.workspace }}/artifacts/*.nupkg" --api-key ${{ secrets.GITHUB_TOKEN }} --source "https://nuget.pkg.github.com/${{ github.repository_owner }}/index.json" - --skip-duplicate + --no-symbols diff --git a/README.md b/README.md index 895bc52..85cdb79 100644 --- a/README.md +++ b/README.md @@ -119,7 +119,15 @@ dotnet build Authorization.sln -c Release dotnet test Authorization.sln -c Release ``` -CI runs on every push and pull request; packages are published from the `main` branch. +CI runs on every push and pull request. + +To release, bump `` in `src/Directory.Build.props` through a PR, then tag the merged commit on `main`: + +```bash +git tag v3.0.0 && git push origin v3.0.0 +``` + +The release workflow fails if the tag does not match the project version or the version already exists on the feed. --- diff --git a/src/Directory.Build.props b/src/Directory.Build.props index 8d0c512..1e304b8 100644 --- a/src/Directory.Build.props +++ b/src/Directory.Build.props @@ -16,9 +16,9 @@ $(NoWarn);CS1591 - + - 2.0.0 + 3.0.0 Isma-L154 Isma-L154 JWT Authorization Middleware