Skip to content

ci(publishing): replace direct NuGet push with ESRP release - #3189

Merged
Gavin Barron (gavinbarron) merged 1 commit into
mainfrom
gavinbarron-esrp-nuget-publishing
Oct 6, 2026
Merged

Gavin Barron (gavinbarron) merged 1 commit into
mainfrom
gavinbarron-esrp-nuget-publishing

Conversation

@gavinbarron

@gavinbarron Gavin Barron (gavinbarron) commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

Changes proposed in this pull request

  • Replace 1ES.PublishNuget@1 direct publishing with EsrpRelease@14, using the existing ESRP service connection, certificates, client ID, and tenant ID, with NuGet organization microsoftgraph.
  • Stage .nupkg and .snupkg files separately from release scripts and wait for ESRP completion before uploading GitHub release assets. Remove the unused NuGet tool installer.
  • Reuse release owners and approvers from the Java and Python SDK pipelines. Preserve build/signing steps, deployment conditions, environment approvals, and GitHub release configuration; no generated API changes.

Other links

Microsoft Reviewers: Open in CodeFlow

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 6, 2026 18:01
@gavinbarron
Gavin Barron (gavinbarron) requested a review from a team as a code owner October 6, 2026 18:01

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The production publishing integration depends on private ESRP configuration that cannot be fully validated from the repository.

Review effort: Balanced
Findings: None

What changed in this PR

Migrates NuGet.org publishing from direct push to ESRP while retaining the existing build, signing, approval, and GitHub release flow.

Changes:

  • Stages NuGet and symbol packages separately.
  • Publishes through EsrpRelease@14.
  • Removes the unused NuGet installer.
File Description
.azure-pipelines/​ci-build.yml Configures ESRP-based NuGet publishing.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@gavinbarron
Gavin Barron (gavinbarron) merged commit 74308b8 into main Oct 6, 2026
7 checks passed
@gavinbarron
Gavin Barron (gavinbarron) deleted the gavinbarron-esrp-nuget-publishing branch October 6, 2026 19:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants