Correct the release path before cutting 3.0.0 - #150
Merged
Merged
Conversation
deploy.yml checked the tag against the csproj only, but SegmentVersion in Version.cs is what the library reports at runtime — Analytics.Version and the library version on every event context. A stale value there would publish a correctly numbered package that misreports itself, with nothing failing. Both are checked now. Restore, build and test use the solution filter, as CI does. Pack is limited to the library project and pushes from a dedicated output folder: a solution-wide pack would also package the sample projects, and the previous **/*.nupkg glob would have pushed them to NuGet. RELEASING.md described tagging before merging, which points the tag at a branch commit, and mentioned only the csproj version in the numbered steps.
release.yml and deploy.yml both trigger on a bare semver tag, so a release fires two publishers at once. Only the collision being masked keeps that from double-pushing: release.yml uses unpinned actions and fails at startup under the org's sha_pinning_required policy, while deploy.yml runs. deploy.yml covers everything release.yml did — same deployment environment and NUGET_API_KEY, same GitHub release — and adds Artifactory OIDC and the version checks.
Merged
wenxi-zeng
approved these changes
Sep 30, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to #146. Release-machinery correctness only — no version bump here, deliberately, so the machinery can be verified before it carries a release.
The tag check missed the version that actually matters
deploy.ymlcompared the tag against<Version>in the csproj only. ButSegmentVersioninSegment/Analytics/Version.csis what the library reports at runtime:Leaving it stale publishes a correctly numbered package whose every event reports the previous version, with nothing failing. Both files are now checked, and the step names whichever disagrees.
Verified locally: passes when both match, fails on a tag mismatch, and fails when the csproj is right but
Version.csis stale.Pack and push were solution-wide
dotnet packran across the whole solution anddotnet nuget push "**/*.nupkg"pushed whatever it found — so the sample projects could be packaged and published to NuGet. Pack is now limited to the library and pushes from a dedicated output folder. Confirmed locally to produce exactly one package,Segment.Analytics.CSharp.2.6.0.nupkg.Restore, build and test also use the
.slnffilter, matchingci.yml.Removed the superseded release workflow
release.ymlanddeploy.ymlboth trigger on a bare semver tag, so a release fires two publishers. That is currently masked rather than handled:release.ymlusescheckout@v3/setup-dotnet@v2/cache@v3and fails at startup undersha_pinning_required, whiledeploy.ymlruns. Anyone repinning it later would get two pushes on one tag.It is not dead code — it published 2.6.0 on 2025-12-04 — but
deploy.ymlcovers everything it did (samedeploymentenvironment andNUGET_API_KEY, same GitHub release) and adds Artifactory OIDC and the version checks.RELEASING.md
Rewritten to match: both version files, tag after merging so the tag points at
mainrather than a branch commit, and thedeploymentenvironment approval step. The OpenUPM (unity/<version>) and pre-release sections are unchanged — both tag conventions are real and coexist, bare for NuGet andunity/for OpenUPM.