Skip to content

ci(release): pack both packages first, timeout, kill obsolete env - #747

Merged
tylerkron merged 1 commit into
mainfrom
cursor/release-yml-robustness-52c6
Sep 21, 2026
Merged

tylerkron merged 1 commit into
mainfrom
cursor/release-yml-robustness-52c6

Conversation

@tylerkron

@tylerkron tylerkron commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

What was wrong

release.yml packed and pushed Daqifi.Core before it had even packed Daqifi.Mcp. If the MCP pack failed, Core was already on nuget.org for that tag with no matching MCP tool, and --skip-duplicate can't repair that on a retry. The job also had GitHub's default 6-hour timeout, set the long-obsolete DOTNET_SKIP_FIRST_TIME_EXPERIENCE, and ran actions/checkout, actions/setup-dotnet and NuGet/login from movable tags, in the one job that holds id-token: write for NuGet Trusted Publishing and the MCP Registry.

How it was fixed

  • New order: pack Core, pack MCP, NuGet login, push Core, push MCP. A pack failure now publishes nothing.
  • timeout-minutes: 45 on publish. Restore/build/test is a few minutes; the MCP-Registry readiness wait is already capped at 10.
  • Dropped DOTNET_SKIP_FIRST_TIME_EXPERIENCE (a no-op since .NET Core 3.0), added DOTNET_NOLOGO, kept telemetry opt-out.
  • SHA-pinned the three actions, matching how the job already checksum-pins mcp-publisher: checkout 3d3c42e (v7.0.1), setup-dotnet a98b568 (v6.0.0), NuGet/login 8d19675 (v1.2.0). Dependabot's github-actions updater keeps SHA pins current.

Unchanged: the id-token: write / contents: read permissions, both NuGet pushes, and the MCP Registry steps from #728 (wait for README, pinned mcp-publisher, version stamp, OIDC login, publish).

Pack Core and MCP nupkgs before either nuget push so a failed MCP pack
cannot leave a tag half-published. Add a job timeout, replace
DOTNET_SKIP_FIRST_TIME_EXPERIENCE with DOTNET_NOLOGO, and SHA-pin the
GitHub Actions (especially third-party NuGet/login).

Co-authored-by: Tyler Kron <tylerkron@gmail.com>
@tylerkron
tylerkron requested a review from a team as a code owner September 17, 2026 10:12
@qodo-code-review

Copy link
Copy Markdown

PR Summary by Qodo

Harden NuGet release sequencing and workflow dependencies

🐞 Bug fix ⚙️ Configuration changes 🕐 10-20 Minutes

Grey Divider

AI Description

• Packs Core and MCP artifacts before publishing to prevent partial NuGet releases.
• Limits release runs to 45 minutes and modernizes .NET environment settings.
• SHA-pins checkout, setup-dotnet, and NuGet login actions for supply-chain integrity.
Diagram

graph TD
  A["Release Event"] --> B["Publish Job"] --> C["Build and Test"] --> D["Pack Core"] --> E["Pack MCP"] --> F["OIDC Login"] --> G["Push Core"] --> H["Push MCP"]
Loading
High-Level Assessment

Packing both artifacts before either push is the best lightweight mitigation because NuGet does not provide transactional multi-package publication or rollback. Separate validation jobs would add artifact-transfer complexity without eliminating failures during the two unavoidable push operations.

Files changed (1) +12 / -7

Other (1) +12 / -7
release.ymlMake the NuGet release workflow safer and bounded +12/-7

Make the NuGet release workflow safer and bounded

• Reorders packaging so both Core and MCP artifacts exist before either NuGet push, reducing the chance of half-published releases. Adds a 45-minute timeout, replaces the obsolete first-time-experience variable with DOTNET_NOLOGO, and SHA-pins all release actions.

.github/workflows/release.yml

@qodo-code-review

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)

Grey Divider

Great, no issues found!

Qodo reviewed your code and found no material issues that require review

Grey Divider

Tip of the day
💡 Did you know, you can enable the Remediation agent and Qodo fixes findings in a dedicated fix PR

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

@tylerkron

Copy link
Copy Markdown
Contributor Author

Reviewed (Claude): approve as is - pack-before-push closes the half-published-release gap, the pinned SHAs match their tags (checked via the GitHub API), and the OIDC permissions, both NuGet pushes and the #728 MCP Registry steps are untouched; actionlint clean apart from pre-existing SC2086 info notes. Qodo-clean on 4151f44, CI green — ready for review.

@tylerkron
tylerkron added this pull request to the merge queue Sep 21, 2026
Merged via the queue into main with commit 44ef6b0 Sep 21, 2026
4 checks passed
@tylerkron
tylerkron deleted the cursor/release-yml-robustness-52c6 branch September 21, 2026 01:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants