From b744eacec629e13fb9fec913bd0ab223bf94ab04 Mon Sep 17 00:00:00 2001 From: Ikiru Yoshizaki <3856350+guitarrapc@users.noreply.github.com> Date: Tue, 6 Oct 2026 17:16:25 +0900 Subject: [PATCH] ci: Improve consistency for nuget publish --- .github/workflows/build-release.yaml | 48 ++++++++++++++++++---------- 1 file changed, 31 insertions(+), 17 deletions(-) diff --git a/.github/workflows/build-release.yaml b/.github/workflows/build-release.yaml index 357eeef..9c17a64 100644 --- a/.github/workflows/build-release.yaml +++ b/.github/workflows/build-release.yaml @@ -12,19 +12,30 @@ on: default: false type: boolean +concurrency: + group: release + cancel-in-progress: false + jobs: + validate-release: + permissions: + contents: read + uses: Cysharp/Actions/.github/workflows/validate-release.yaml@main + with: + tag: ${{ inputs.tag }} + build-dotnet: + needs: [validate-release] permissions: contents: read - id-token: write # required for NuGet Trusted Publish runs-on: ubuntu-24.04 timeout-minutes: 10 steps: - uses: Cysharp/Actions/.github/actions/checkout@main - uses: Cysharp/Actions/.github/actions/setup-dotnet@main # pack nuget (.nupkg and .symbols.nupkg will be created) - - run: dotnet build -c Release -p:Version=${{ inputs.tag }} - - run: dotnet pack -c Release --no-build -p:Version=${{ inputs.tag }} -p:IncludeSymbols=true -o ./publish + - run: dotnet build -c Release -p:Version=${{ needs.validate-release.outputs.tag }} + - run: dotnet pack -c Release --no-build -p:Version=${{ needs.validate-release.outputs.tag }} -p:IncludeSymbols=true -o ./publish - uses: Cysharp/Actions/.github/actions/upload-artifact@main with: name: nuget @@ -34,29 +45,32 @@ jobs: name: UnitGenerator path: ./src/UnitGenerator/bin/Release/netstandard2.0/UnitGenerator.dll retention-days: 1 - # push nuget - - name: NuGet login (OIDC) - uses: NuGet/login@8d196754b4036150537f80ac539e15c2f1028841 # v1.2.0 - id: login - with: - user: ${{ secrets.NUGET_USER }} - - run: dotnet nuget push "./publish/*.nupkg" --skip-duplicate -s https://api.nuget.org/v3/index.json -k "${NUGET_KEY}" - if: ${{ !inputs.dry-run }} - env: - NUGET_KEY: ${{ steps.login.outputs.NUGET_API_KEY }} # release create-release: - needs: [build-dotnet] + needs: [validate-release, build-dotnet] permissions: contents: write - id-token: write # required for NuGet Trusted Publish uses: Cysharp/Actions/.github/workflows/create-release.yaml@main with: commit-id: "" dry-run: ${{ inputs.dry-run }} - tag: ${{ inputs.tag }} - nuget-push: false + tag: ${{ needs.validate-release.outputs.tag }} release-upload: true release-asset-path: ./UnitGenerator/UnitGenerator.dll secrets: inherit + + publish-package: + needs: [validate-release, create-release] + if: ${{ !inputs.dry-run }} + permissions: + contents: read + id-token: write # required for NuGet Trusted Publish in the calling repository + runs-on: ubuntu-24.04 + timeout-minutes: 10 + steps: + - uses: Cysharp/Actions/.github/actions/publish-nuget@main + with: + artifact-name: nuget + user: ${{ secrets.NUGET_USER }} + version: ${{ needs.validate-release.outputs.version }}