Add a package smoke test gate before publishing to nuget.org - #2068
Conversation
Nothing today actually restores the packed .nupkg files as a real consumer would before pushing to nuget.org - the existing "test" jobs in windows.yml/manylinux.yml/macos.yml only ever exercise loose build output with the native binary copied in by hand, never the packaging path itself (RID asset placement, dependency graph). Added test/OpenCvSharp.PackageSmokeTest, a plain console app that references OpenCvSharp5 (+ a platform runtime package) via PackageReference rather than ProjectReference, with the package version and runtime package id supplied at build time via MSBuild properties so it always targets whatever is about to be published. publish_nuget.yml now runs it against a local feed built from the release-packages artifact, on both windows-latest and ubuntu-latest, and Publish's needs now include this job so a broken package blocks the nuget.org push instead of only being noticed after the fact. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
📝 WalkthroughWalkthroughA new .NET 10 executable validates generated OpenCvSharp NuGet packages on Windows and Ubuntu. The publish workflow runs the test against release artifacts and requires successful completion before publishing. ChangesNuGet package smoke testing
Estimated code review effort: 3 (Moderate) | ~20 minutes Sequence Diagram(s)sequenceDiagram
participant Prepare
participant PackageSmokeTest
participant OpenCvSharp.PackageSmokeTest
participant Publish
Prepare->>PackageSmokeTest: Download release-packages
PackageSmokeTest->>OpenCvSharp.PackageSmokeTest: Run with selected package version and runtime
OpenCvSharp.PackageSmokeTest-->>PackageSmokeTest: Return success or failure
PackageSmokeTest-->>Publish: Complete dependency
Publish->>Publish: Publish NuGet packages
Possibly related PRs
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/publish_nuget.yml:
- Around line 271-279: Update the “Run package smoke test” step to remove the
dotnet nuget add source command and avoid direct GitHub expression interpolation
in the bash script. Pass the workspace release-packages path and version/runtime
values through environment variables, then provide the local package feed via
the dotnet run MSBuild RestoreAdditionalProjectSources property so the source is
scoped to this execution.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Pro
Run ID: b2069399-dc49-435d-847d-c4bc8f67979a
📒 Files selected for processing (3)
.github/workflows/publish_nuget.ymltest/OpenCvSharp.PackageSmokeTest/OpenCvSharp.PackageSmokeTest.csprojtest/OpenCvSharp.PackageSmokeTest/Program.cs
…aw expression interpolation
dotnet nuget add source wrote to the runner's global NuGet.Config (state that
could leak on a self-hosted runner, or be defeated by a repo-level
NuGet.Config with <clear/>), and the step interpolated ${{ }} expressions
directly into the bash script (zizmor template-injection finding). Replaced
the local feed with -p:RestoreAdditionalProjectSources (scoped to this
restore only) and routed the version/runtime-package values through env: instead
of inline expression interpolation.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
There was a problem hiding this comment.
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (1)
.github/workflows/publish_nuget.yml (1)
233-282: 🔒 Security & Privacy | 🟡 Minor | ⚡ Quick winAdd an explicit permissions block. This workflow inherits the default
GITHUB_TOKENscope; set the minimum permissions it needs instead.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.github/workflows/publish_nuget.yml around lines 233 - 282, Add an explicit top-level permissions block for the workflow containing only the minimum GITHUB_TOKEN permissions required by the publish and PackageSmokeTest jobs. Ensure existing checkout, artifact download, package publishing, and smoke-test behavior remains unchanged.Source: Linters/SAST tools
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Outside diff comments:
In @.github/workflows/publish_nuget.yml:
- Around line 233-282: Add an explicit top-level permissions block for the
workflow containing only the minimum GITHUB_TOKEN permissions required by the
publish and PackageSmokeTest jobs. Ensure existing checkout, artifact download,
package publishing, and smoke-test behavior remains unchanged.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Pro
Run ID: 0a697e4d-6001-478e-9254-ccf08ab61fa6
📒 Files selected for processing (1)
.github/workflows/publish_nuget.yml
Summary
.nupkgfiles as a real consumer would before pushing to nuget.org. The existing "test" jobs inwindows.yml/manylinux.yml/macos.ymlonly ever exercise loose build output with the native binary copied in by hand - never the packaging path itself (RID asset placement, missing files, dependency graph across theOpenCvSharp5*package family). A packaging mistake would only be noticed after users hit it in production.test/OpenCvSharp.PackageSmokeTest: a plain console app (same style astest/OpenCvSharp.Tests.NativeAot) that referencesOpenCvSharp5plus a platform runtime package viaPackageReference, notProjectReference. Since package versions are date-stamped at pack time, the version and which runtime package to pull are supplied at build time via MSBuild properties (-p:SmokeTestPackageVersion=.../-p:SmokeTestRuntimePackage=...) rather than hardcoded, so the project always targets whatever is actually about to be published.publish_nuget.ymlgets a newPackageSmokeTestjob (matrix:windows-latest+ubuntu-latest) that runs betweenPrepareandPublish: it adds thePreparejob'srelease-packagesartifact as a local NuGet feed, then builds and runs the smoke test project against it.Publish'sneedsnow includes this job, so a broken package blocks the nuget.org push instead of only being caught after the fact.OpenCvSharp5.Windowson Windows,OpenCvSharp5.official.runtime.linux-x64on Linux), not slim/headless/macOS/arm64/wasm - this is meant as a cheap, low-maintenance safety net rather than exhaustive coverage.Testing
.github/workflows/publish_nuget.ymlparses as well-formed YAML (yaml.safe_load).PackageSmokeTestjob locally, since it depends on therelease-packagesartifact produced byPrepare(itself built from artifacts across several other workflows); this needs apublish_nuget.ymlrun (workflow_dispatch) to validate end-to-end.🤖 Generated with Claude Code
Summary by CodeRabbit