Package publishing (GitHub Packages + nuget.org)
Policies that keep the org coherent
Novolis uses two feeds:
| When | Feed | Workflow |
|---|---|---|
Merge to main when the package surface changes | GitHub Packages and nuget.org | merge.yml → dotnet-merge-publish.yml |
| GitHub Release published | GitHub Packages, and the packages attached to that release | release.yml → dotnet-release-publish.yml |
PRs only build and test (pull-request.yml).
GitHub Packages feed
https://nuget.pkg.github.com/Novolis-Platform/index.jsonPublishing on merge uses GITHUB_TOKEN (packages: write) for packages in that repository.
Cross-repo dependencies
GITHUB_TOKEN cannot restore packages published from other Novolis repos. For repos that reference Novolis.* from GitHub Packages, add an organization secret:
| Secret | Scopes | Purpose |
|---|---|---|
NOVOLIS_GPR_TOKEN | read:packages | CI restore of Novolis packages from other repos |
Public on GitHub Packages means any authenticated GitHub user can download them (your existing gh token is enough for local restore). It does not mean anonymous NuGet restore: unauthenticated requests to nuget.pkg.github.com return 401. Configure credentials once in user %APPDATA%\NuGet\NuGet.Config via configure-gpr-user-nuget.ps1; never commit tokens into repo nuget.config.
See github-packages-org-settings.md for org defaults.
nuget.org
Library merge.yml pushes to nuget.org with Trusted Publishing (NuGet/login, user frankhaugen, id-token: write) in a job of that caller workflow. novolis-tools and novolis-analyzers do the same from release.yml. A library release.yml packs, pushes to GitHub Packages, and attaches .nupkg / .snupkg to the GitHub Release.
Consuming packages
Each repo has a nuget.config with nuget.org + GitHub feed mapping (Novolis.* → github) only — no credentials in git.
Local restore: run once per machine:
.\novolis-governance\scripts\configure-gpr-user-nuget.ps1That writes the github source and token into %APPDATA%\NuGet\NuGet.Config. Re-run after gh auth token rotation.
Scripts
| Script | Purpose |
|---|---|
configure-gpr-user-nuget.ps1 | User-level GitHub Packages credentials (%APPDATA%\NuGet\NuGet.Config) |
gpr-health-check.ps1 | One-shot feed + float + nuget-only health check |
gpr-package-overview.ps1 | Org package inventory (latest, repo link, junk flags) |
gpr-find-junk-versions.ps1 / gpr-remove-junk-versions.ps1 | Find/delete throwaway versions that poison 2026.1.* |
find-build-line-floats.ps1 | Fail on 2026.1.N.* floats in Directory.Packages.props |
configure-package-publishing.ps1 | Version props, targets, nuget.config, workflows |
apply-pr-merge-release-workflows.ps1 | Write pull-request.yml, merge.yml, release.yml; remove ci.yml |
See gpr-maintenance.md for the operational runbook.