Skip to content

Compute the package version from the git tags instead of nuget.org - #1350

Merged
meziantou merged 1 commit into
mainfrom
feature/ci-version-git-tags-69f2a3
Aug 27, 2026
Merged

meziantou merged 1 commit into
mainfrom
feature/ci-version-git-tags-69f2a3

Conversation

@meziantou

Copy link
Copy Markdown
Owner

What

The compute_package_version job of the CI computed the version of the next package by querying nuget.org for the latest published version. It now derives it from the git tags.

Why

The create_release job already creates a tag named after the version for every published package, so the tags are an equally accurate source, and computing a version no longer requires nuget.org to be reachable.

How

  • The job now checks out the repository (it previously had no checkout step) with fetch-depth: 0 so that all the tags are fetched, and filter: tree:0 to keep the clone cheap by skipping the file contents.
  • The script takes the greatest 3.0.N tag and increments it. It fails with an ::error:: annotation when no matching tag is found, instead of silently computing 3.0.1.

Why not fetch-tags: true

That would be cheaper, but it is not reliable here. actions/checkout implements the flag by dropping --no-tags, which leaves git's tag auto-following, and under the default shallow fetch that only brings the tags pointing at the fetched commit. Tested against this repository, it fetched exactly one tag; on a PR branch, or on main once a commit lands after the last release, it would have fetched none and the job would have failed. The all-history refspec includes +refs/tags/*:refs/tags/* explicitly, which fetches all 481 tags.

Testing

The run block was extracted from the YAML and executed with pwsh against the real tags of the repository:

Case Result
refs/heads/main 3.0.184
Pull request ref 3.0.184-build.<run_id>
Repository without tags Error annotation, exit 1

The previous nuget.org based logic, run side by side, also yields 3.0.184, so the two agree. The workflow file still parses and all its jobs are intact.

Note for the reviewer

The source of truth for the version moves from "what is published on nuget.org" to "what create_release tagged". The two can diverge if deploy succeeds but create_release fails: the next run would recompute the same version and dotnet nuget push --skip-duplicate would quietly skip the push instead of failing. The window is narrow, as the tag is created right after the deploy, but it did not exist before. Moving the tag creation before the push would close it, if that is worth doing.

The compute_package_version job queried nuget.org to find the latest
published version. Use the git tags instead: the create_release job
already creates a tag named after the version for every published
package, so the tags are an equally accurate source and the CI no longer
depends on nuget.org being reachable to compute a version.

The job now checks out the repository with fetch-depth: 0 so that all the
tags are fetched, and filter: tree:0 to keep the clone cheap by skipping
the file contents. fetch-tags: true is not enough: actions/checkout
implements it by dropping --no-tags, which leaves git's tag
auto-following, and under the default shallow fetch that only brings the
tags pointing at the fetched commit.

The job also fails with an error annotation when no 3.0.* tag is found,
instead of silently computing 3.0.1.
@meziantou
meziantou merged commit a386ff8 into main Aug 27, 2026
13 checks passed
@meziantou
meziantou deleted the feature/ci-version-git-tags-69f2a3 branch August 27, 2026 01:39
This was referenced Aug 27, 2026
IhateTrains pushed a commit to ParadoxGameConverters/ImperatorToCK3 that referenced this pull request Aug 27, 2026
Updated
[Meziantou.Analyzer](https://github.com/meziantou/Meziantou.Analyzer)
from 3.0.177 to 3.0.184.

<details>
<summary>Release notes</summary>

_Sourced from [Meziantou.Analyzer's
releases](https://github.com/meziantou/Meziantou.Analyzer/releases)._

## 3.0.184

NuGet package:
<https://www.nuget.org/packages/Meziantou.Analyzer/3.0.184>

## What's Changed
* Compute the package version from the git tags instead of nuget.org by
@​meziantou in meziantou/Meziantou.Analyzer#1350


**Full Changelog**:
meziantou/Meziantou.Analyzer@3.0.183...3.0.184

## 3.0.183

NuGet package:
<https://www.nuget.org/packages/Meziantou.Analyzer/3.0.183>

## What's Changed
* Fix MA0026 crash on an unterminated block comment (#​1328) by
@​meziantou in meziantou/Meziantou.Analyzer#1346
* Fix MA0050 code fixer producing an extension local function (CS1106)
by @​meziantou in
meziantou/Meziantou.Analyzer#1348
* Fix MA0028 code fixer producing uncompilable code (#​1327) by
@​meziantou in meziantou/Meziantou.Analyzer#1347
* Fail the tests when an analyzer throws by @​meziantou in
meziantou/Meziantou.Analyzer#1349


**Full Changelog**:
meziantou/Meziantou.Analyzer@3.0.182...3.0.183

## 3.0.182

NuGet package:
<https://www.nuget.org/packages/Meziantou.Analyzer/3.0.182>

## What's Changed
* Fix MA0073 code fixer producing uncompilable code for low-precedence
operands by @​meziantou in
meziantou/Meziantou.Analyzer#1344
* Do not crash on an invalid regex in the .editorconfig (MA0003, MA0104)
by @​meziantou in
meziantou/Meziantou.Analyzer#1345


**Full Changelog**:
meziantou/Meziantou.Analyzer@3.0.181...3.0.182

## 3.0.181

NuGet package:
<https://www.nuget.org/packages/Meziantou.Analyzer/3.0.181>

## What's Changed
* Add a language attribute code fix and MA0218/MA0219 for XML comments
by @​meziantou in
meziantou/Meziantou.Analyzer#1320
* Compile the text produced by the fixer in the test harness by
@​meziantou in meziantou/Meziantou.Analyzer#1342
* Fix StackOverflow crash on cyclic local initializers
(MA0091/MA0092/MA0093) by @​meziantou in
meziantou/Meziantou.Analyzer#1341
* Avoid the Sqlite data-flow analysis on every MA0042 invocation by
@​meziantou in meziantou/Meziantou.Analyzer#1343


**Full Changelog**:
meziantou/Meziantou.Analyzer@3.0.180...3.0.181

## 3.0.180

NuGet package:
<https://www.nuget.org/packages/Meziantou.Analyzer/3.0.180>

## What's Changed
* Fix MAS0004 stopping at the first unrelated CA1507 diagnostic by
@​meziantou in meziantou/Meziantou.Analyzer#1340


**Full Changelog**:
meziantou/Meziantou.Analyzer@3.0.179...3.0.180

## 3.0.179

NuGet package:
<https://www.nuget.org/packages/Meziantou.Analyzer/3.0.179>

## What's Changed
* Fix bare `#pragma warning disable` in AvoidUsingRedundantElseAnalyzer
by @​meziantou in
meziantou/Meziantou.Analyzer#1339


**Full Changelog**:
meziantou/Meziantou.Analyzer@3.0.178...3.0.179

## 3.0.178

NuGet package:
<https://www.nuget.org/packages/Meziantou.Analyzer/3.0.178>

## What's Changed
* Fix MA0075 false positive on FormattableString.Invariant by
@​meziantou in meziantou/Meziantou.Analyzer#1322


**Full Changelog**:
meziantou/Meziantou.Analyzer@3.0.177...3.0.178

Commits viewable in [compare
view](meziantou/Meziantou.Analyzer@3.0.177...3.0.184).
</details>

[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=Meziantou.Analyzer&package-manager=nuget&previous-version=3.0.177&new-version=3.0.184)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
This was referenced Sep 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant