CI: bound and pin reusable NuGet deployment - #8
Conversation
There was a problem hiding this comment.
💡 Codex Review
On pull_request runs, this checkout loads the PR's version of the workflow, validator, and tests, so a PR that weakens deploy-nuget.yml can also replace these commands with a no-op while preserving the required job name and receiving a green check. The full-file hashes therefore provide no enforcement because the code verifying them is controlled by the same change; run the policy implementation from a protected base revision or an external immutable workflow while passing it the proposed files to inspect.
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Closes #7
Summary
.nuspecstructure, and records size and SHA-256 without reading deployment secrets or containing sign/publish stepsubuntu-slimcaller that creates a minimal NuGet artifact and invokes the same-commit reusable workflow withdry-run: trueRunner and cost decision
The real deploy job stays on hosted
windows-latestbecause its optional signing path uses PowerShell and Windows signing tooling. The 10-minute cap is about 5.3× P95 and 3.8× the observed maximum, preserving bounded network/signing headroom without a blanket 60-minute allowance.The policy and dry-run jobs use hosted
ubuntu-slimwith three-minute caps. The corrected literal-head proof consumed 9 seconds to create/upload the fixture and 11 seconds to download/inspect it. No self-hosted runner or production credential/feed was used, and the Windows deployment job was skipped before runner allocation.GitHub does not support conditionally required
workflow_callsecrets.apiKeyis therefore optional during reusable-call validation, while an early guard in the mutually exclusive real-deploy job rejects a missing API key before artifact download, signing, or publication. Normal signing and publication inputs remain unchanged.Validation
node --test scripts/validate-deploy-workflow-policy.test.mjs— 47/47 passed on Node 24.16.0node scripts/validate-deploy-workflow-policy.mjs— passedgit diff --check— passedb88a8796ede661dcd98604bf8786d12254dda373/f5810c7f33d929cd73dc6b7c295f159603528d1dubuntu-slimin 7 secondsb88a8796ede661dcd98604bf8786d12254dda373; fixture 9 seconds, artifact inspection 11 seconds, production Windows job skippedAppPortal.WorkflowDryRun.0.0.0.nupkgas 870 bytes with SHA-256743418eb87a1b54cd5e35c8ae6e80454bd13bb0a2fe1ba483113aa75257861cfDraft status and external settings
The credential-free exact-head reusable-workflow exit criterion is exercised and green. This PR remains draft intentionally and has no requested reviewers.
mastercurrently has no branch protection. Requiring the policy and dry-run checks is therefore a repository-owner ruleset/branch-protection task; repository-local policy cannot guarantee its own future execution.Merge method: the signing action is pinned to intermediate branch commit
0836b48f03b9309fe1bcadda6109d9e761e5aaef. Merge this PR with a normal merge commit. Do not squash or rebase-merge unless that pin is first moved to an already-merged durable commit.