Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
50 changes: 49 additions & 1 deletion .github/workflows/publish_nuget.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ on:
workflow_dispatch:

jobs:
Publish:
Prepare:
runs-on: ubuntu-24.04

steps:
Expand Down Expand Up @@ -104,6 +104,54 @@ jobs:
dotnet run --project tool/OpenCvSharp.NupkgBetaRemover --configuration Release -- "$f"
done

- name: Verify no beta versions remain
run: |
if find . -maxdepth 1 -name "*-beta*" -type f | grep -q .; then
echo "ERROR: beta packages still exist after rename"
find . -maxdepth 1 -name "*-beta*" -type f
exit 1
fi
Comment on lines +107 to +113

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major

Verify no beta versions remain misses nuspec-internal beta strings.

Line 109 only checks filenames. The previous breakage was a nuspec <version> mismatch, so this gate can still pass while publishing broken packages.

🔧 Proposed hardening
       - name: Verify no beta versions remain
         run: |
-          if find . -maxdepth 1 -name "*-beta*" -type f | grep -q .; then
-            echo "ERROR: beta packages still exist after rename"
-            find . -maxdepth 1 -name "*-beta*" -type f
-            exit 1
-          fi
+          set -euo pipefail
+          if find . -maxdepth 1 -type f -name "*-beta*" | grep -q .; then
+            echo "ERROR: beta package filenames still exist after rename"
+            find . -maxdepth 1 -type f -name "*-beta*"
+            exit 1
+          fi
+
+          failed=0
+          for pkg in *.nupkg *.snupkg; do
+            [ -f "$pkg" ] || continue
+            nuspec=$(unzip -Z1 "$pkg" '*.nuspec' | head -n1 || true)
+            [ -n "$nuspec" ] || continue
+            if unzip -p "$pkg" "$nuspec" | grep -Eq -- '-beta([.-]?[0-9]+)?'; then
+              echo "ERROR: beta marker still present in nuspec: $pkg"
+              failed=1
+            fi
+          done
+          [ "$failed" -eq 0 ]
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In @.github/workflows/publish_nuget.yml around lines 107 - 113, The "Verify no
beta versions remain" workflow step only scans filenames and misses beta markers
inside package metadata (e.g., .nuspec <version> tags); update that step to also
search file contents for "-beta" (at least in .nuspec files and other package
metadata) and fail if any matches are found, e.g., run a content grep for
"-beta" (or specifically for <version>.*-beta.*</version>) across .nuspec and
related files so the job fails on internal version strings as well as filenames.


- name: List packages to publish
run: |
echo "=== Packages ready for publishing ==="
ls -lh *.nupkg *.snupkg 2>/dev/null || true

echo "## NuGet Packages to Publish" >> $GITHUB_STEP_SUMMARY
echo "" >> $GITHUB_STEP_SUMMARY
echo "| Package | Size |" >> $GITHUB_STEP_SUMMARY
echo "|---------|------|" >> $GITHUB_STEP_SUMMARY
for f in *.nupkg; do
[ -f "$f" ] || continue
size=$(du -h "$f" | cut -f1)
echo "| \`${f}\` | ${size} |" >> $GITHUB_STEP_SUMMARY
done
echo "" >> $GITHUB_STEP_SUMMARY
echo "**Total:** $(find . -maxdepth 1 -name '*.nupkg' | wc -l) nupkg, $(find . -maxdepth 1 -name '*.snupkg' | wc -l) snupkg" >> $GITHUB_STEP_SUMMARY

- name: Upload release packages
uses: actions/upload-artifact@v6
with:
name: release-packages
path: |
*.nupkg
*.snupkg
retention-days: 7

Publish:
needs: Prepare
runs-on: ubuntu-24.04
environment: nuget-production

steps:
- name: Download release packages
uses: actions/download-artifact@v6
with:
name: release-packages

- name: List packages
run: ls -lh *.nupkg *.snupkg 2>/dev/null || true

- name: Push to nuget.org
run: |
dotnet nuget push "*.nupkg" -k ${{secrets.NUGET_ORG_API_KEY}} -s https://api.nuget.org/v3/index.json --skip-duplicate
Expand Down
8 changes: 2 additions & 6 deletions tool/OpenCvSharp.NupkgBetaRemover/Program.cs
Original file line number Diff line number Diff line change
Expand Up @@ -34,13 +34,9 @@
nuspecContent = nuspecContentStreamReader.ReadToEnd();
}

if (nupkgFile.Contains("ubuntu"))
nuspecContent = Regex.Replace(nuspecContent, @"-beta-?\d*</version>", "</version>");
if (!nupkgFile.Contains("ubuntu"))
{
nuspecContent = Regex.Replace(nuspecContent, @"-\d+</version>", $".{date:yyyyMMdd}</version>");
}
else
{
nuspecContent = Regex.Replace(nuspecContent, @"-beta-?\d*</version>", "</version>");
nuspecContent = Regex.Replace(nuspecContent, @"(?<=<dependency.*version="")(?<version>\d{1,2}\.\d{1,2}\.\d{1,2}\.\d{8})(?<betaVersion>-beta-?\d*)",
match => match.Groups["version"].Value);
}
Expand Down
Loading