GitHub Packages — organization settings (Novolis-Platform)
Policies that keep the org coherent
Published Novolis NuGet packages should be public so any authenticated GitHub user (gh token) and CI GITHUB_TOKEN can restore them without an org-wide NOVOLIS_GPR_TOKEN. Public does not mean anonymous: the NuGet feed still requires authentication on every request.
Required one-time org setting (makes new publishes public by default)
Open: Novolis-Platform → Settings → Packages
Under Package creation:
- Enable Public
- Disable Private (and Internal unless you need it)
GitHub documents this as choosing the visibility members publish by default. After this change, new package versions published from CI should be public without using the UI per package.
Under Default package settings:
- Enable Inherit access from source repository
Existing private packages
GitHub’s Packages REST API has no endpoint to change NuGet visibility (PATCH .../packages/nuget/{name}/visibility returns 404; there is no gh package command). Visibility is UI-only, or delete + republish.
After enabling Public package creation above (disable Private / Internal if you want new publishes to default to public):
- Packages → package → Package settings → Change visibility → Public, or
- Delete the private package and merge to
mainagain so CI republishes (with org Public creation enabled).
Local bulk delete (then merge/republish per repo):
gh auth refresh -h github.com -s read:packages,write:packages,delete:packages
.\novolis-governance\scripts\set-org-nuget-packages-public.ps1 -ListOnly
.\novolis-governance\scripts\set-org-nuget-packages-public.ps1 -DeletePrivateCI
Merge publish (merge.yml) pushes to GitHub Packages. Package visibility is set in the org UI (the REST visibility API is not available for org NuGet packages).
Publishing sets RepositoryUrl via Novolis.GitHubPackages.props so packages link to their source repo.
Dogfooding restore
- CI:
GITHUB_TOKENwithpackages: read(noNOVOLIS_GPR_TOKENwhen packages are public and linked). - Local:
.\novolis-governance\scripts\configure-gpr-user-nuget.ps1(user%APPDATA%\NuGet\NuGet.Config, not reponuget.config)