Use official Dart publishing - #128
Merged
Merged
Conversation
Contributor
There was a problem hiding this comment.
🟡 Changes recommended
The publish workflow’s tag trigger pattern won’t match intended semver tags (glob vs regex), and the publish job is missing required contents: read permissions for checkout within the reusable workflow.
Get a fresh assessment by requesting another Copilot review.
Pull request overview
This PR updates the package publishing automation to use Dart’s official OIDC-based publishing workflow (reusable workflow) instead of a third-party publisher, and adds a pre-publish verification job to run dart pub publish --dry-run and flutter test before publishing.
Changes:
- Switch the release publish workflow to call
dart-lang/setup-dart’s officialpublish.ymlreusable workflow with OIDC (id-token). - Add a
verifyjob that installs Flutter, disables analytics, runs a publish dry run, and runs tests before the publish job. - Update the standalone “dry run” workflow to use the same local dry-run + test steps (no stored pub credentials).
File summaries
| File | Description |
|---|---|
| .github/workflows/pub_publish.yml | Moves publishing to the official Dart reusable workflow and adds a verify gate before publishing. |
| .github/workflows/pub_publish_dry_run.yml | Replaces third-party dry-run publishing with dart pub publish --dry-run plus flutter test. |
Review details
- Files reviewed: 2/2 changed files
- Comments generated: 2
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
nohli
force-pushed
the
ci/replace-dart-publisher
branch
from
September 18, 2026 09:28
6976c71 to
f2f6636
Compare
nohli
force-pushed
the
update-flutter-3-44-agp9
branch
from
September 18, 2026 09:28
8cc565c to
ac0a2b2
Compare
nohli
force-pushed
the
ci/replace-dart-publisher
branch
2 times, most recently
from
September 18, 2026 12:18
e1e37c5 to
080c99f
Compare
nohli
force-pushed
the
ci/replace-dart-publisher
branch
2 times, most recently
from
September 18, 2026 12:33
36f1b72 to
d92df0d
Compare
nohli
force-pushed
the
update-flutter-3-44-agp9
branch
from
September 24, 2026 15:27
5d4c528 to
3ef04aa
Compare
nohli
force-pushed
the
ci/replace-dart-publisher
branch
from
September 24, 2026 15:33
d92df0d to
bde515c
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Switches android_id from the third-party publishing action to Dart's official OIDC workflow. Releases now have to pass a publish dry run and the package tests before pub.dev receives them. OIDC uses a short-lived token, so the repository no longer needs a stored pub credential.
One-time pub.dev setup
Before the first release from this workflow:
fluttercommunity/android_id.{{version}}.The workflow expects a bare version tag such as
1.2.3, and that tag must matchversion:inpubspec.yaml. NoPUB_CREDENTIALSsecret is needed. The full setup is covered in the official Dart publishing guide.Validation
Validated locally with Flutter 3.47.5: package and example analysis and tests, a publish dry run with no warnings, and an Android release build.
This PR is stacked on #126 and should be merged after it.