ci: add a release workflow (this repo has none) - #27
Merged
Merged
Conversation
This repository had no release automation. v1.0.0 and v1.0.1 were packed and pushed by hand, and v1.0.2 -- the security release clearing five HIGH advisories across eight packages -- was tagged with nothing published, because a tag here triggers only ci, docs and codeql. Ports the pattern already used across the family, with two additions specific to what this repository needs: 1. A version gate that runs before anything is packed. Every packable project's <Version> and every 'dotnet add package ... --version' snippet in tracked Markdown must match the tag. CHANGELOG.md is excluded -- version mentions there are facts about earlier releases, not instructions. The equivalent gate in postquantum-file-encryption rejected a v1.7.0 tag over exactly this class of mismatch before anything reached nuget.org. 2. conda-forge OpenSSL 3.5+ plus a zero-skip assertion. The stock ubuntu runner predates 3.5, so MLKem.IsSupported is false and the PqcFact guard skips the whole crypto suite -- 56 tests, silently. A release must not be cut from a run where the cryptographic paths never executed, so the workflow fails if any test skips. Mirrors the setup added to ci.yml. Publishing uses Trusted Publishing (short-lived OIDC token, no stored API key), matching postquantum-securechannel and PostQuantum.Hybrid. REQUIRES ONE-TIME SETUP: a nuget.org Trusted Publishing policy for (systemslibrarian, PostQuantum.DataProtection, release.yml). Until that exists the NuGet/login step fails and nothing is pushed; every step before it still runs, so a premature tag yields a verifiable GitHub release without publishing and is safe to retry. Verified: YAML parses, and the gate passes against the current tree at 1.0.2. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
This repository has no release automation.
v1.0.0andv1.0.1were packed and pushed by hand, and I confirmed a tag here triggers onlyci,docsandcodeql.That is why
v1.0.2is tagged with nothing published — the security release clearing five HIGH advisories across all eight packages. Consumers are still resolving 1.0.1 and the vulnerableSystem.Security.Cryptography.Xml 8.0.3.What's here
Ports the family pattern (closest to
postquantum-securechannel), with two additions this repo specifically needs:1. A version gate, before anything is packed. Every packable project's
<Version>and everydotnet add package … --versionsnippet in tracked Markdown must match the tag.CHANGELOG.mdexcluded — those are facts about past releases, not instructions.The equivalent gate in
postquantum-file-encryptionrejected av1.7.0tag today over exactly this, before anything reached nuget.org.postquantum-aspnetcorelacked the snippet half of it and shipped three releases telling users to install0.8.0-preview.1.2. conda-forge OpenSSL 3.5+ and a zero-skip assertion. The stock ubuntu runner predates 3.5, so
MLKem.IsSupportedis false, thePqcFactguard skips the whole crypto suite — 56 tests, silently — and a green run proves nothing. This workflow installs a PQ-capable OpenSSL and fails if any test skips. Mirrors what went intoci.yml, where the Linux lane now reportsMLKem.IsSupported = TrueandPassed: 108, Skipped: 0.One-time setup required
Publishing uses Trusted Publishing — no stored API key. It needs a policy on nuget.org:
Until that exists the
NuGet/loginstep fails and nothing is pushed. Every step before it still runs, so a tag pushed before setup produces a verifiable GitHub release without publishing — safe to retry after.Verified
YAML parses (ruby). Gate dry-run against the current tree: all 8 csproj at
1.0.2, zero install snippets to check → passes.Getting 1.0.2 out
Once this merges and the nuget.org policy exists, re-point the tag:
git tag -f v1.0.2 && git push -f origin v1.0.2Or publish by hand as before — the workflow is about the next release either way.
🤖 Generated with Claude Code