Repository navigation
ci: feedz.io empty-key wording + pass push keys via env (#8600 follow-up) - #1121
Conversation
…a env (#8600 follow-up)
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 6 remain after this review. 📝 WalkthroughWalkthroughThe Feedz and nuget.org publishing steps now pass API keys through step-scoped ChangesPackage publishing
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~8 minutes Change: Other Suggested reviewers: Merge Risk: ⚪ Minimal · up to No actionable merge-blocking risk is established in the changed publishing workflow. Architecture SummaryArchitecture risk: 🔵 Low · up to The changed surface does not map to a changed system, dependency edge, entrypoint, or external dependency. Changed systems: None identified. Architecture concerns Review detailsBefore / after behavior
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
sfmskywalker
left a comment
There was a problem hiding this comment.
Elsa 3 Code Review: APPROVE + HIGH @ 90f5b8b
Code Review, Round 1/4
Scope: .github/workflows/packages.yml +8/-4. Fixes N1 and N2 from #1120 (elsa-core#8600 follow-up).
Verdict: No blockers.
Checks
- Same source as before.
Publish to feedz.ionow hasenv: API_KEY: ${{ secrets.FEEDZ_API_KEY }}, the expression it previously put on the command line. It matches its guard.Publish to nuget.orgnow hasenv: API_KEY: ${{ steps.nuget_login.outputs.NUGET_API_KEY }}, the same OIDC output as before and as its guard.- Nothing reads
secrets.NUGET_API_KEY.
- Quoting and exposure.
- The key is passed as
-k "$API_KEY"/--api-key "$API_KEY", double-quoted. - No
${{ }}key expression is left on any command line. - Nothing echoes the key, and there is no
set -x.
- The key is passed as
- Conditions. The
if:lines are identical to the base, including the!startsWith(needs.build.outputs.version, '3.10.')guard onpublish_nuget_nuget. No step-levelif:was added. - Messages.
- feedz.io now names only
FEEDZ_API_KEY. - nuget.org now points at the OIDC login output and the Trusted Publishing policy.
- Both still say nothing was pushed and are followed by
exit 1.
- feedz.io now names only
- actionlint. 1.7.7 with shellcheck reports 16 findings on both base and head, and none are new.
- Consistency with elsa-extensions#277. The four steps match line for line: same
env:, same guard text, same quoting. The only differences are pre-existing ones: the package download path, the--api-key/--sourcevs-k/-sflags, and the env var name for the feed URL.
Non-blocking
- N1. "repository secret" is not accurate here. The feedz.io message says "Check the FEEDZ_API_KEY repository secret". For elsa-studio,
FEEDZ_API_KEYexists only at organization level; there is no repository-level copy. Saying "the FEEDZ_API_KEY secret (repository or organization)" would point operators to the right place. Keep the wording the same as in extensions.
Bots and CI on 90f5b8bb
- CI: all green: Build and test, CodeQL (all Analyze jobs), GitGuardian and CLA. Merge state is CLEAN.
- Greptile: 5/5 at
90f5b8bb(advisory). - CodeRabbit: no actionable comments.
- Bugbot: did not run.
- Threads: none.
Gate: APPROVE + HIGH and green CI on 90f5b8bb. Met.
Follow-up to elsa-workflows/elsa-core#8600 (Code Review non-blocking items on the empty-key guard PR).
FEEDZ_API_KEYrepository secret only. That job never uses the NuGet login (OIDC) step. The nuget.org error now points at the OIDC login output and the Trusted Publishing policy.dotnet nuget pushsteps take the key from a step-levelenv: API_KEYand use"$API_KEY", instead of interpolating${{ }}into the command line.No behaviour change otherwise. Each check still reads exactly what its push uses, and the conditions are unchanged.
Summary by CodeRabbit