Skip to content

Add a package smoke test gate before publishing to nuget.org - #2068

Merged
shimat merged 2 commits into
mainfrom
add-package-smoke-test
Jul 19, 2026
Merged

shimat merged 2 commits into
mainfrom
add-package-smoke-test

Conversation

@shimat

@shimat shimat commented Jul 19, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Nothing in the release pipeline today actually restores the packed .nupkg files as a real consumer would before pushing to nuget.org. The existing "test" jobs in windows.yml/manylinux.yml/macos.yml only ever exercise loose build output with the native binary copied in by hand - never the packaging path itself (RID asset placement, missing files, dependency graph across the OpenCvSharp5* package family). A packaging mistake would only be noticed after users hit it in production.
  • Added test/OpenCvSharp.PackageSmokeTest: a plain console app (same style as test/OpenCvSharp.Tests.NativeAot) that references OpenCvSharp5 plus a platform runtime package via PackageReference, not ProjectReference. Since package versions are date-stamped at pack time, the version and which runtime package to pull are supplied at build time via MSBuild properties (-p:SmokeTestPackageVersion=... / -p:SmokeTestRuntimePackage=...) rather than hardcoded, so the project always targets whatever is actually about to be published.
  • publish_nuget.yml gets a new PackageSmokeTest job (matrix: windows-latest + ubuntu-latest) that runs between Prepare and Publish: it adds the Prepare job's release-packages artifact as a local NuGet feed, then builds and runs the smoke test project against it. Publish's needs now includes this job, so a broken package blocks the nuget.org push instead of only being caught after the fact.
  • Scope is intentionally narrow for now: only the default "full" flavor is exercised (OpenCvSharp5.Windows on Windows, OpenCvSharp5.official.runtime.linux-x64 on Linux), not slim/headless/macOS/arm64/wasm - this is meant as a cheap, low-maintenance safety net rather than exhaustive coverage.

Testing

  • Validated .github/workflows/publish_nuget.yml parses as well-formed YAML (yaml.safe_load).
  • Could not exercise the new PackageSmokeTest job locally, since it depends on the release-packages artifact produced by Prepare (itself built from artifacts across several other workflows); this needs a publish_nuget.yml run (workflow_dispatch) to validate end-to-end.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features
    • Added an automated NuGet package smoke test that runs during the publish flow on Windows and Ubuntu against the exact package versions being released.
  • Bug Fixes
    • Publishing is now blocked if the packaged native assets fail validation (including image processing, encoding/decoding, ORB feature detection, and DNN blob creation).
  • Tests
    • Introduced a dedicated smoke-test executable targeting .NET 10 to validate the end-to-end OpenCV behavior of the published runtime packages.

Nothing today actually restores the packed .nupkg files as a real consumer
would before pushing to nuget.org - the existing "test" jobs in
windows.yml/manylinux.yml/macos.yml only ever exercise loose build output with
the native binary copied in by hand, never the packaging path itself (RID
asset placement, dependency graph). Added test/OpenCvSharp.PackageSmokeTest,
a plain console app that references OpenCvSharp5 (+ a platform runtime
package) via PackageReference rather than ProjectReference, with the package
version and runtime package id supplied at build time via MSBuild properties
so it always targets whatever is about to be published. publish_nuget.yml now
runs it against a local feed built from the release-packages artifact, on
both windows-latest and ubuntu-latest, and Publish's needs now include this
job so a broken package blocks the nuget.org push instead of only being
noticed after the fact.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@shimat shimat self-assigned this Jul 19, 2026
@coderabbitai

coderabbitai Bot commented Jul 19, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

A new .NET 10 executable validates generated OpenCvSharp NuGet packages on Windows and Ubuntu. The publish workflow runs the test against release artifacts and requires successful completion before publishing.

Changes

NuGet package smoke testing

Layer / File(s) Summary
Smoke-test project and OpenCV validation
test/OpenCvSharp.PackageSmokeTest/*
Adds a non-packable .NET 10 executable with versioned OpenCvSharp package references and checks ORB processing, image round-tripping, and DNN blob creation.
Publish workflow gate
.github/workflows/publish_nuget.yml
Downloads release packages, runs Windows and Ubuntu matrix smoke tests, and makes Publish depend on PackageSmokeTest.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Sequence Diagram(s)

sequenceDiagram
  participant Prepare
  participant PackageSmokeTest
  participant OpenCvSharp.PackageSmokeTest
  participant Publish
  Prepare->>PackageSmokeTest: Download release-packages
  PackageSmokeTest->>OpenCvSharp.PackageSmokeTest: Run with selected package version and runtime
  OpenCvSharp.PackageSmokeTest-->>PackageSmokeTest: Return success or failure
  PackageSmokeTest-->>Publish: Complete dependency
  Publish->>Publish: Publish NuGet packages
Loading

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the main change: adding a smoke-test gate before publishing packages to NuGet.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch add-package-smoke-test

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/publish_nuget.yml:
- Around line 271-279: Update the “Run package smoke test” step to remove the
dotnet nuget add source command and avoid direct GitHub expression interpolation
in the bash script. Pass the workspace release-packages path and version/runtime
values through environment variables, then provide the local package feed via
the dotnet run MSBuild RestoreAdditionalProjectSources property so the source is
scoped to this execution.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: b2069399-dc49-435d-847d-c4bc8f67979a

📥 Commits

Reviewing files that changed from the base of the PR and between 88c0ec5 and 736491a.

📒 Files selected for processing (3)
  • .github/workflows/publish_nuget.yml
  • test/OpenCvSharp.PackageSmokeTest/OpenCvSharp.PackageSmokeTest.csproj
  • test/OpenCvSharp.PackageSmokeTest/Program.cs

Comment thread .github/workflows/publish_nuget.yml
…aw expression interpolation

dotnet nuget add source wrote to the runner's global NuGet.Config (state that
could leak on a self-hosted runner, or be defeated by a repo-level
NuGet.Config with <clear/>), and the step interpolated ${{ }} expressions
directly into the bash script (zizmor template-injection finding). Replaced
the local feed with -p:RestoreAdditionalProjectSources (scoped to this
restore only) and routed the version/runtime-package values through env: instead
of inline expression interpolation.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
.github/workflows/publish_nuget.yml (1)

233-282: 🔒 Security & Privacy | 🟡 Minor | ⚡ Quick win

Add an explicit permissions block. This workflow inherits the default GITHUB_TOKEN scope; set the minimum permissions it needs instead.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/publish_nuget.yml around lines 233 - 282, Add an explicit
top-level permissions block for the workflow containing only the minimum
GITHUB_TOKEN permissions required by the publish and PackageSmokeTest jobs.
Ensure existing checkout, artifact download, package publishing, and smoke-test
behavior remains unchanged.

Source: Linters/SAST tools

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Outside diff comments:
In @.github/workflows/publish_nuget.yml:
- Around line 233-282: Add an explicit top-level permissions block for the
workflow containing only the minimum GITHUB_TOKEN permissions required by the
publish and PackageSmokeTest jobs. Ensure existing checkout, artifact download,
package publishing, and smoke-test behavior remains unchanged.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 0a697e4d-6001-478e-9254-ccf08ab61fa6

📥 Commits

Reviewing files that changed from the base of the PR and between 736491a and 0d0c1e9.

📒 Files selected for processing (1)
  • .github/workflows/publish_nuget.yml

@shimat
shimat merged commit 7bd2fc3 into main Jul 19, 2026
14 checks passed
@shimat
shimat deleted the add-package-smoke-test branch July 19, 2026 17:36
@shimat shimat added the enhancement New feature or improvement to OpenCvSharp label Jul 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or improvement to OpenCvSharp

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant