This document describes how to create and publish releases for DropBear.Codex.
DropBear.Codex uses calendar versioning with Nerdbank.GitVersioning:
- Format:
YYYY.MM.patch - Example:
2025.10.0,2025.10.1,2025.11.0
Current version is defined in version.json.
- Write access to the repository
NUGET_API_KEYsecret configured in GitHub repository settings- Clean working directory (no uncommitted changes)
- On
masterbranch with latest changes pulled
- All CI workflows passing on
masterbranch - All intended changes merged from
developtomaster -
CHANGELOG.mdupdated with release notes under[Unreleased] - Security issues documented in
SECURITY.md - Breaking changes clearly documented
-
README.mdstill matches the current target framework, project inventory, and workflow badge links - Package metadata remains aligned with the mono-repo identity and current NuGet descriptions/tags
- Review workflow annotations and distinguish real failures from upstream GitHub Action runtime deprecation noise before blocking a release
Edit version.json to set the new version:
{
"version": "2025.11" // Update this
}Important: Only update the version field. Do not modify other settings.
Move changes from [Unreleased] to a new version section:
## [Unreleased]
(Leave empty for future changes)
## [2025.11.0] - 2025-11-15
### Added
- Feature descriptions...
### Changed
- Change descriptions...
### Fixed
- Fix descriptions...git add version.json CHANGELOG.md
git commit -m "chore: Bump version to 2025.11.0"
git push origin masterOption A: Using the Helper Script (Recommended)
# From repository root
.\create-release-tag.ps1 -Version "2025.11.0"The script will:
- Validate version format
- Verify you're on master branch
- Check working directory is clean
- Create annotated tag with changelog
- Push tag to trigger release workflow
Option B: Manual Process
# Verify you're on master
git checkout master
git pull origin master
# Create annotated tag (use v prefix!)
git tag -a v2025.11.0 -m "Release 2025.11.0
## Highlights
- Feature 1
- Feature 2
- Security fix
See CHANGELOG.md for full details."
# Verify tag
git tag -l "v2025.11.0"
git show v2025.11.0
# Push tag to trigger release workflow
git push origin v2025.11.0- Go to Actions
- Watch the "Release (NuGet)" workflow
- Verify all steps complete successfully:
- ✅ Build
- ✅ Pack
- ✅ Validate Packages
- ✅ Publish to NuGet
- ✅ Create GitHub Release
NuGet.org:
- Check packages are live: https://www.nuget.org/packages?q=DropBear.Codex
- Verify all projects published
- Check package metadata is correct
- Spot-check package descriptions, repository/project URLs, and supported framework claims
GitHub Release:
- Verify release created: https://github.com/tkuchel/DropBear.Codex/releases
- Confirm release notes populated
- Check assets attached (if any)
- Announce release (if needed)
- Update dependent projects
- Monitor for issues
Correct:
v2025.10.0 ✅ Correct
v2025.11.0 ✅ Correct
v2026.1.0 ✅ CorrectIncorrect:
2025.10.0 ❌ Missing 'v' prefix
v2025.10 ❌ Missing patch version
v2025.10.0.1 ❌ Too many version parts
release-2025 ❌ Wrong formatIncrement when the calendar year changes:
2025.12.5→2026.1.0
Increment for monthly feature releases:
2025.10.0→2025.11.0
Auto-incremented by Nerdbank.GitVersioning based on commit height. Manually set to 0 when bumping year or month:
2025.10.5→2025.11.0(new month, reset to 0)
If a release has critical issues:
# Install dotnet CLI if needed
dotnet tool install -g dotnet-nuget-unlister
# Unlist the broken version
dotnet nuget delete DropBear.Codex.Core 2025.11.0 --api-key YOUR_API_KEY --source https://api.nuget.org/v3/index.json --non-interactiveNote: This doesn't delete the package, just hides it from search results.
Create hotfix branch, fix issues, test thoroughly.
Bump patch version and follow normal release process:
2025.11.0(broken) →2025.11.1(fixed)
# Delete local tag
git tag -d v2025.11.0
# Delete remote tag (CAUTION!)
git push origin :refs/tags/v2025.11.0
# Recreate tag correctly
git tag -a v2025.11.0 -m "Release 2025.11.0"
git push origin v2025.11.0-
Check workflow logs in GitHub Actions
-
Common issues:
NUGET_API_KEYnot configured or expired- Network issues with NuGet.org
- Package validation failed
- Build errors
-
Fix issue and re-run workflow or delete tag and recreate
- Unlist the incorrect version on NuGet.org
- Fix version.json
- Create new tag with correct version
- Publish corrected version
For security fixes:
- Do not publicly discuss vulnerability before release
- Prepare fix in private branch
- Follow normal release process
- After publication, update SECURITY.md
- Publish security advisory on GitHub
For critical production issues:
# 1. Create hotfix branch from master
git checkout master
git pull origin master
git checkout -b hotfix/v2025.11.1
# 2. Apply fix and test
# ... make changes ...
git add .
git commit -m "fix: Critical issue description"
# 3. Merge to master
git checkout master
git merge hotfix/v2025.11.1
git push origin master
# 4. Follow normal release process
.\create-release-tag.ps1 -Version "2025.11.1"
# 5. Merge back to develop
git checkout develop
git merge master
git push origin develop- CHANGELOG.md - Release history
- SECURITY.md - Security policy and known issues
- CONTRIBUTING.md - Development guidelines
- version.json - Version configuration
- ci.yml: Runs on every push/PR
- release.yml: Triggered by version tags (
v*) - codeql.yml: Security analysis
This repository currently forces JavaScript-based GitHub Actions to run on Node 24. If workflow annotations still mention Node 20 deprecation for pinned actions, treat that as an upstream action-maintainer reminder unless the workflow itself is failing. Keep the pinned SHAs current as part of normal release hygiene.
- Check existing releases
- Review GitHub Actions
- Open an issue