ci(release): pack both packages first, timeout, kill obsolete env - #747
Conversation
Pack Core and MCP nupkgs before either nuget push so a failed MCP pack cannot leave a tag half-published. Add a job timeout, replace DOTNET_SKIP_FIRST_TIME_EXPERIENCE with DOTNET_NOLOGO, and SHA-pin the GitHub Actions (especially third-party NuGet/login). Co-authored-by: Tyler Kron <tylerkron@gmail.com>
PR Summary by QodoHarden NuGet release sequencing and workflow dependencies
AI Description
Diagram
High-Level Assessment
Files changed (1)
|
Code Review by Qodo🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)
Great, no issues found!Qodo reviewed your code and found no material issues that require reviewTip of the day💡 Did you know, you can enable the Remediation agent and Qodo fixes findings in a dedicated fix PR |
|
Reviewed (Claude): approve as is - pack-before-push closes the half-published-release gap, the pinned SHAs match their tags (checked via the GitHub API), and the OIDC permissions, both NuGet pushes and the #728 MCP Registry steps are untouched; actionlint clean apart from pre-existing SC2086 info notes. Qodo-clean on 4151f44, CI green — ready for review. |
What was wrong
release.ymlpacked and pushedDaqifi.Corebefore it had even packedDaqifi.Mcp. If the MCP pack failed, Core was already on nuget.org for that tag with no matching MCP tool, and--skip-duplicatecan't repair that on a retry. The job also had GitHub's default 6-hour timeout, set the long-obsoleteDOTNET_SKIP_FIRST_TIME_EXPERIENCE, and ranactions/checkout,actions/setup-dotnetandNuGet/loginfrom movable tags, in the one job that holdsid-token: writefor NuGet Trusted Publishing and the MCP Registry.How it was fixed
timeout-minutes: 45onpublish. Restore/build/test is a few minutes; the MCP-Registry readiness wait is already capped at 10.DOTNET_SKIP_FIRST_TIME_EXPERIENCE(a no-op since .NET Core 3.0), addedDOTNET_NOLOGO, kept telemetry opt-out.mcp-publisher: checkout3d3c42e(v7.0.1), setup-dotneta98b568(v6.0.0), NuGet/login8d19675(v1.2.0). Dependabot's github-actions updater keeps SHA pins current.Unchanged: the
id-token: write/contents: readpermissions, both NuGet pushes, and the MCP Registry steps from #728 (wait for README, pinnedmcp-publisher, version stamp, OIDC login, publish).