Skip to content

ci: prevent tag-dispatch dry runs from publishing NuGet packages - #33

Merged
AGiorgetti merged 3 commits into
developfrom
feat/codex-issue-19-publish-gate
Oct 5, 2026
Merged

AGiorgetti merged 3 commits into
developfrom
feat/codex-issue-19-publish-gate

Conversation

@AGiorgetti

@AGiorgetti AGiorgetti commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

A manual dispatch on a tag with dry_run=true could reach the production NuGet publish job even when publish=false. Require a push event for automatic tag publishing; retain explicit manual publishing on main/release//hotfix/ with publish=true, dry_run=false, successful artifact prerequisites, and production approval.

Fixes #19.

Changes

  • One production condition line changed; package validation, provenance/checksums, environment protection, and publishing commands are preserved.
  • Add 154 MSTest cases evaluating actual workflow expressions and dependencies: the 96 event/ref/input cases, 48 failed/cancelled/skipped prerequisite cases, tag rehearsals, authorized stable/prerelease tag pushes and manual branch publishing, unsupported events, and absent inputs.
  • Execute the extracted publishing script only with local dotnet mocking and a fake key. Dry runs must schedule no publish job and record zero pushes.
  • Synchronize release checklist, changelog, and issue-specific control-document evidence.

Validation

  • Test-first baseline on unchanged YAML: 20 failed, 134 passed, zero skipped. Both tag rehearsals recorded three mocked push calls, including publish=false; non-dry-run tag dispatches already skipped pack despite the unsafe raw publish expression.
  • Fixed focused suite: 173/173 passed, zero skipped (154 new + 19 existing release-quality cases).
  • Release solution build: zero warnings/errors. YAML parsing and CRLF-aware whitespace checks pass.
  • Full solution run: 806 passed, 2 failed due to stale sample NuGet assets (NETSDK1064), 1 Native AOT prerequisite skip. Regenerating assets and rebuilding recovered both failures; affected tests plus release regressions then passed 175/175, zero skipped. All 808 executed cases have passing evidence across the full run and targeted recovery, not a single all-green full-suite invocation.
  • Independent read-only review accepted the change and coverage. Exact-head ordinary PR CI passed; detailed results follow.

Exact-head CI

CI run 37113397730 completed successfully for pull_request on 34d0549132b50bf0c0e09dd6e143ea1d26f7ea66.

  • Both Windows and Linux full suites: 809 passed per platform, zero failures/skips (568 generator, 235 packaging, 5 runtime, 1 integration). This includes all new publishing regressions and required trimming/Native AOT validation.
  • All six Roslyn host jobs passed (4.8.0, 4.14.0, 5.9.0 on both platforms).
  • Pack & Validate, Verify Release Artifacts, and Publish NuGet Packages were all skipped.
  • Remote branch, PR head, and CI head match. PR remains draft against develop; working tree is clean.

Limits

The local evaluator covers the current Actions expression subset and dependency graph, not live production approval behavior. Local Native AOT is inconclusive because the MSVC C++ linker toolchain is absent. No release workflow was dispatched, no real NuGet push ran, and no tags, security settings, or merges were changed. AgentStack CLI layout incompatibility required the repository-authorized GitHub CLI fallback.

Prepared with OpenAI Codex.

AGiorgetti and others added 2 commits October 3, 2026 11:18
Refs #19

Co-authored-by: Codex <codex@openai.com>
Fixes #19. Preserve explicit manual branch publishing and production artifact gates.

Co-authored-by: Codex <codex@openai.com>

@AGiorgetti AGiorgetti left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The changelog is wrong! the fix should be listed in a "## Fixes" section in a new "## Unreleased" section (top of the file) instead of updating an already existing release

Co-authored-by: Codex <codex@openai.com>
@AGiorgetti
AGiorgetti merged commit c79b1a2 into develop Oct 5, 2026
11 checks passed
@AGiorgetti
AGiorgetti deleted the feat/codex-issue-19-publish-gate branch October 5, 2026 10:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[P1] Prevent tag-based workflow dry runs from entering the NuGet publish job

1 participant