Novolis Docs
novolis-governance / nuget-setup.md

Package publishing (GitHub Packages + nuget.org)

dotnetgovernancenovolis

Novolis uses two feeds:

WhenFeedWorkflow
Merge to main when the package surface changesGitHub Packages and nuget.orgmerge.yml → dotnet-merge-publish.yml
GitHub Release publishedGitHub Packages, and the packages attached to that releaserelease.yml → dotnet-release-publish.yml

PRs only build and test (pull-request.yml).

GitHub Packages feed

https://nuget.pkg.github.com/Novolis-Platform/index.json

Publishing on merge uses GITHUB_TOKEN (packages: write) for packages in that repository.

Cross-repo dependencies

GITHUB_TOKEN cannot restore packages published from other Novolis repos. For repos that reference Novolis.* from GitHub Packages, add an organization secret:

SecretScopesPurpose
NOVOLIS_GPR_TOKENread:packagesCI restore of Novolis packages from other repos

Public on GitHub Packages means any authenticated GitHub user can download them (your existing gh token is enough for local restore). It does not mean anonymous NuGet restore: unauthenticated requests to nuget.pkg.github.com return 401. Configure credentials once in user %APPDATA%\NuGet\NuGet.Config via configure-gpr-user-nuget.ps1; never commit tokens into repo nuget.config.

See github-packages-org-settings.md for org defaults.

nuget.org

Library merge.yml pushes to nuget.org with Trusted Publishing (NuGet/login, user frankhaugen, id-token: write) in a job of that caller workflow. novolis-tools and novolis-analyzers do the same from release.yml. A library release.yml packs, pushes to GitHub Packages, and attaches .nupkg / .snupkg to the GitHub Release.

Consuming packages

Each repo has a nuget.config with nuget.org + GitHub feed mapping (Novolis.* → github) only — no credentials in git.

Local restore: run once per machine:

.\novolis-governance\scripts\configure-gpr-user-nuget.ps1

That writes the github source and token into %APPDATA%\NuGet\NuGet.Config. Re-run after gh auth token rotation.

Scripts

ScriptPurpose
configure-gpr-user-nuget.ps1User-level GitHub Packages credentials (%APPDATA%\NuGet\NuGet.Config)
gpr-health-check.ps1One-shot feed + float + nuget-only health check
gpr-package-overview.ps1Org package inventory (latest, repo link, junk flags)
gpr-find-junk-versions.ps1 / gpr-remove-junk-versions.ps1Find/delete throwaway versions that poison 2026.1.*
find-build-line-floats.ps1Fail on 2026.1.N.* floats in Directory.Packages.props
configure-package-publishing.ps1Version props, targets, nuget.config, workflows
apply-pr-merge-release-workflows.ps1Write pull-request.yml, merge.yml, release.yml; remove ci.yml

See gpr-maintenance.md for the operational runbook.