Remove Feedz publishing from CI - #1380
Merged
Merged
Conversation
Packages were pushed to the Feedz feed for every non-main branch. Drop that branch of the publish step so CI only pushes to nuget.org, and gate the push (and the OIDC NuGet login it depends on) on the main branch.
This was referenced Sep 6, 2026
Closed
This was referenced Sep 25, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
Removes the Feedz feed from the
deployjob of.github/workflows/ci.yml:Publish NuGet packagesstep no longer branches onGITHUB_REF. It always pushes to nuget.org, and the whole step is gated ongithub.ref == 'refs/heads/main'— previously theelsebranch (non-main) is what pushed tohttps://f.feedz.io/meziantou/meziantou-analyzer/nuget/index.json.FeedzApiKeyenv var and itssecrets.FEEDZ_APIKEYusage.NuGet login (OIDC → temp API key)step onmainas well, since its only consumer is the push step. It was previously minting a temporary nuget.org API key on every non-fork PR run with nothing left to use it.Why
Feedz publishing of CI builds is no longer wanted.
Notes for reviewers
deployjob itself still runs on PRs (it checks out, downloads thenugetartifact and sets up .NET), so any required status check ondeploykeeps reporting instead of being skipped. Both remaining publish-related steps simply no-op offmain.feedzreference remains in the repo.FEEDZ_APIKEYrepository secret is now unused and can be deleted in the GitHub settings.