Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
57 changes: 57 additions & 0 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,57 @@
name: Release

# Publishes the QueryKit package to nuget.org at the version a git tag sets. MinVer turns an
# annotated tag `v1.14.2` into package version 1.14.2 (see QueryKit/QueryKit.csproj), so releasing
# is `git tag -a v1.14.2 -m ... && git push origin v1.14.2`. Tag a commit that already passed CI on
# main. workflow_dispatch is a manual re-run; --skip-duplicate makes a re-push a no-op.
#
# Auth is NuGet Trusted Publishing (OIDC) - no long-lived API key secret. This job mints a GitHub
# OIDC token, NuGet/login exchanges it for a 1-hour nuget.org key that matches a Trusted Publishing
# policy configured on nuget.org (owner pdevito3, repo QueryKit, workflow file release.yml). The
# only config on GitHub is the non-secret NUGET_USER (your nuget.org profile name).

on:
push:
tags: [ 'v*' ]
workflow_dispatch:

jobs:
publish:
runs-on: ubuntu-latest
permissions:
id-token: write # mint the OIDC token NuGet exchanges for a short-lived key
contents: read # checkout
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0 # MinVer needs full history + tags to compute the version

- uses: actions/setup-dotnet@v4
with:
dotnet-version: 10.0.x

- name: Restore
run: dotnet restore

- name: Build
run: dotnet build --no-restore -c Release

# Pack only the shipped package by explicit path - never the unit tests, integration tests,
# WebApiTestProject, or SharedTestingHelper projects, even though they build.
- name: Pack
run: dotnet pack QueryKit/QueryKit.csproj --no-restore -c Release -o "${{ runner.temp }}/nupkgs"

# Exchange the job's OIDC token for a short-lived nuget.org API key (valid 1 hour). Done right
# before the push so it can't expire mid-run. `user` is your nuget.org profile name, not email.
- name: NuGet login (OIDC -> short-lived key)
uses: NuGet/login@v1
id: nuget-login
with:
user: ${{ secrets.NUGET_USER }}

- name: Push to nuget.org
run: >
dotnet nuget push "${{ runner.temp }}/nupkgs/*.nupkg"
--api-key ${{ steps.nuget-login.outputs.NUGET_API_KEY }}
--source https://api.nuget.org/v3/index.json
--skip-duplicate
3 changes: 2 additions & 1 deletion QueryKit/QueryKit.csproj
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@
<Nullable>enable</Nullable>
<PackageId>QueryKit</PackageId>
<PackageTags>QueryKit;Filter;Filtering;Sort;Sorting</PackageTags>
<Version>1.14.2</Version>
<MinVerTagPrefix>v</MinVerTagPrefix>
<Authors>Paul DeVito</Authors>
<Summary>QueryKit is a .NET library that makes it easier to query your data by providing a fluent and intuitive syntax for filtering and sorting.</Summary>
<Description>QueryKit is a .NET library that makes it easier to query your data by providing a fluent and intuitive syntax for filtering and sorting.</Description>
Expand All @@ -25,6 +25,7 @@
<ItemGroup>
<PackageReference Include="Sprache" Version="2.3.1" />
<PackageReference Include="Ardalis.SmartEnum" Version="8.2.0" />
<PackageReference Include="MinVer" Version="6.0.0" PrivateAssets="all" />
</ItemGroup>

</Project>
Loading