Skip to content

ci: add a release workflow (this repo has none) - #27

Merged
systemslibrarian merged 1 commit into
mainfrom
ci/release-workflow
Aug 20, 2026
Merged

systemslibrarian merged 1 commit into
mainfrom
ci/release-workflow

Conversation

@systemslibrarian

Copy link
Copy Markdown
Owner

Why

This repository has no release automation. v1.0.0 and v1.0.1 were packed and pushed by hand, and I confirmed a tag here triggers only ci, docs and codeql.

That is why v1.0.2 is tagged with nothing published — the security release clearing five HIGH advisories across all eight packages. Consumers are still resolving 1.0.1 and the vulnerable System.Security.Cryptography.Xml 8.0.3.

What's here

Ports the family pattern (closest to postquantum-securechannel), with two additions this repo specifically needs:

1. A version gate, before anything is packed. Every packable project's <Version> and every dotnet add package … --version snippet in tracked Markdown must match the tag. CHANGELOG.md excluded — those are facts about past releases, not instructions.

The equivalent gate in postquantum-file-encryption rejected a v1.7.0 tag today over exactly this, before anything reached nuget.org. postquantum-aspnetcore lacked the snippet half of it and shipped three releases telling users to install 0.8.0-preview.1.

2. conda-forge OpenSSL 3.5+ and a zero-skip assertion. The stock ubuntu runner predates 3.5, so MLKem.IsSupported is false, the PqcFact guard skips the whole crypto suite — 56 tests, silently — and a green run proves nothing. This workflow installs a PQ-capable OpenSSL and fails if any test skips. Mirrors what went into ci.yml, where the Linux lane now reports MLKem.IsSupported = True and Passed: 108, Skipped: 0.

One-time setup required

Publishing uses Trusted Publishing — no stored API key. It needs a policy on nuget.org:

account → Trusted Publishing → add policy for (systemslibrarian, PostQuantum.DataProtection, release.yml)

Until that exists the NuGet/login step fails and nothing is pushed. Every step before it still runs, so a tag pushed before setup produces a verifiable GitHub release without publishing — safe to retry after.

Verified

YAML parses (ruby). Gate dry-run against the current tree: all 8 csproj at 1.0.2, zero install snippets to check → passes.

Getting 1.0.2 out

Once this merges and the nuget.org policy exists, re-point the tag:

git tag -f v1.0.2 && git push -f origin v1.0.2

Or publish by hand as before — the workflow is about the next release either way.

🤖 Generated with Claude Code

This repository had no release automation. v1.0.0 and v1.0.1 were packed and
pushed by hand, and v1.0.2 -- the security release clearing five HIGH advisories
across eight packages -- was tagged with nothing published, because a tag here
triggers only ci, docs and codeql.

Ports the pattern already used across the family, with two additions specific to
what this repository needs:

1. A version gate that runs before anything is packed. Every packable project's
   <Version> and every 'dotnet add package ... --version' snippet in tracked
   Markdown must match the tag. CHANGELOG.md is excluded -- version mentions
   there are facts about earlier releases, not instructions. The equivalent gate
   in postquantum-file-encryption rejected a v1.7.0 tag over exactly this class
   of mismatch before anything reached nuget.org.

2. conda-forge OpenSSL 3.5+ plus a zero-skip assertion. The stock ubuntu runner
   predates 3.5, so MLKem.IsSupported is false and the PqcFact guard skips the
   whole crypto suite -- 56 tests, silently. A release must not be cut from a run
   where the cryptographic paths never executed, so the workflow fails if any
   test skips. Mirrors the setup added to ci.yml.

Publishing uses Trusted Publishing (short-lived OIDC token, no stored API key),
matching postquantum-securechannel and PostQuantum.Hybrid.

REQUIRES ONE-TIME SETUP: a nuget.org Trusted Publishing policy for
(systemslibrarian, PostQuantum.DataProtection, release.yml). Until that exists
the NuGet/login step fails and nothing is pushed; every step before it still
runs, so a premature tag yields a verifiable GitHub release without publishing
and is safe to retry.

Verified: YAML parses, and the gate passes against the current tree at 1.0.2.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@systemslibrarian
systemslibrarian merged commit bd95791 into main Aug 20, 2026
4 of 5 checks passed
@systemslibrarian
systemslibrarian deleted the ci/release-workflow branch August 20, 2026 05:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant