Skip to content

Use official Dart publishing - #128

Merged
nohli merged 4 commits into
update-flutter-3-44-agp9from
ci/replace-dart-publisher
Sep 25, 2026
Merged

nohli merged 4 commits into
update-flutter-3-44-agp9from
ci/replace-dart-publisher

Conversation

@nohli

@nohli nohli commented Sep 18, 2026 •

Copy link
Copy Markdown
Member

Switches android_id from the third-party publishing action to Dart's official OIDC workflow. Releases now have to pass a publish dry run and the package tests before pub.dev receives them. OIDC uses a short-lived token, so the repository no longer needs a stored pub credential.

One-time pub.dev setup

Before the first release from this workflow:

  1. Open the android_id Admin page.
  2. Under Automated publishing, enable publishing from GitHub Actions.
  3. Set Repository to fluttercommunity/android_id.
  4. Set Tag pattern to {{version}}.
  5. Enable publishing from push events. Leave workflow-dispatch publishing and a required GitHub Actions environment disabled.
  6. Save the configuration and confirm that pub.dev shows success.

The workflow expects a bare version tag such as 1.2.3, and that tag must match version: in pubspec.yaml. No PUB_CREDENTIALS secret is needed. The full setup is covered in the official Dart publishing guide.

Validation

Validated locally with Flutter 3.47.5: package and example analysis and tests, a publish dry run with no warnings, and an Android release build.

This PR is stacked on #126 and should be merged after it.

Copilot AI lite review requested due to automatic review settings September 18, 2026 03:58

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The publish workflow’s tag trigger pattern won’t match intended semver tags (glob vs regex), and the publish job is missing required contents: read permissions for checkout within the reusable workflow.

Get a fresh assessment by requesting another Copilot review.

Pull request overview

This PR updates the package publishing automation to use Dart’s official OIDC-based publishing workflow (reusable workflow) instead of a third-party publisher, and adds a pre-publish verification job to run dart pub publish --dry-run and flutter test before publishing.

Changes:

  • Switch the release publish workflow to call dart-lang/setup-dart’s official publish.yml reusable workflow with OIDC (id-token).
  • Add a verify job that installs Flutter, disables analytics, runs a publish dry run, and runs tests before the publish job.
  • Update the standalone “dry run” workflow to use the same local dry-run + test steps (no stored pub credentials).
File summaries
File Description
.github/workflows/pub_publish.yml Moves publishing to the official Dart reusable workflow and adds a verify gate before publishing.
.github/workflows/pub_publish_dry_run.yml Replaces third-party dry-run publishing with dart pub publish --dry-run plus flutter test.
Review details
  • Files reviewed: 2/2 changed files
  • Comments generated: 2
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/pub_publish.yml Outdated
Comment thread .github/workflows/pub_publish.yml
@nohli
nohli force-pushed the ci/replace-dart-publisher branch from 6976c71 to f2f6636 Compare September 18, 2026 09:28
@nohli
nohli force-pushed the update-flutter-3-44-agp9 branch from 8cc565c to ac0a2b2 Compare September 18, 2026 09:28
@nohli
nohli force-pushed the ci/replace-dart-publisher branch 2 times, most recently from e1e37c5 to 080c99f Compare September 18, 2026 12:18
@nohli
nohli force-pushed the ci/replace-dart-publisher branch 2 times, most recently from 36f1b72 to d92df0d Compare September 18, 2026 12:33
@nohli
nohli force-pushed the update-flutter-3-44-agp9 branch from 5d4c528 to 3ef04aa Compare September 24, 2026 15:27
@nohli
nohli force-pushed the ci/replace-dart-publisher branch from d92df0d to bde515c Compare September 24, 2026 15:33
@nohli
nohli requested a lite review from Copilot September 24, 2026 16:03

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No unresolved blocking issues were identified.

Review effort: Lite
Findings: None

Resolved since last review (2)

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Fix the release tag glob and add dependency resolution before dry runs.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 High severity

Open (1)

Comment thread .github/workflows/pub_publish.yml

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Add dependency installation before tests in both workflows.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 2 Medium severity

Open (2)
Resolved since last review (1)

Comment thread .github/workflows/pub_publish.yml
Comment thread .github/workflows/pub_publish_dry_run.yml

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No unresolved review issues were identified.

Review effort: Lite
Findings: None

Resolved since last review (2)

@nohli
nohli merged commit 7e635b2 into update-flutter-3-44-agp9 Sep 25, 2026
13 checks passed
@nohli
nohli deleted the ci/replace-dart-publisher branch September 25, 2026 20:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants