Releasing
NuGet publish is tag-triggered. The workflow is .github/workflows/publish.yml. It authenticates with nuget.org Trusted Publishing (NuGet/login + OIDC), not a long-lived API key. The nuget.org policy must name this repository and publish.yml. The GitHub secret NUGET_USER is the nuget.org profile name.
Version
VersionPrefix is 7.0.0. That release references Dynamitey.Community 4.0.0 and targets netstandard2.0 and net10.0. It is the last release that supports .NET Standard 2.0, and so the last release a .NET Framework 4.6.1 through 4.8.1 application can take.
8.0.0 drops netstandard2.0 and targets net10.0 and net11.0 (#108, milestone). The target date is 10 November 2026. It follows Dynamitey.Community 5.0.0. Not another 5.x.
Cut a release
First make sure CHANGELOG.md has a ## [version] section that describes the release. Then, on master, after CI is green:
git tag vX.Y.Z
git push origin vX.Y.Z
The Publish workflow will:
- Extract the
## [X.Y.Z]section ofCHANGELOG.mdfor the tagged version, and fail if there isn't one - Restore, build
-warnaserror, test - Pack
FSharp.Interop.DynamicatX.Y.Z(nupkg + snupkg) - Attest SLSA build provenance for the nupkg and snupkg, signed with Sigstore through GitHub's OIDC identity
dotnet nuget pushto nuget.org with--skip-duplicate- Create the GitHub release
vX.Y.Zwith those notes, the packages, and the provenance bundleFSharp.Interop.Dynamic.X.Y.Z.intoto.jsonlattached. A version with a-suffix is marked as a prerelease.
workflow_dispatch with a version input does steps 1–5 without a tag and creates no GitHub release. Prefer the tag.
Verify a package
Anyone can check that a package was built by this repository's Publish workflow:
gh attestation verify FSharp.Interop.Dynamic.X.Y.Z.nupkg --repo fsprojects/FSharp.Interop.Dynamic
Pull requests never publish.
After it lands
Confirm nuget.org lists the new version and that README / getting-started install instructions match it. After 7.0.0, the next planned major is 8.0.0 on 10 November 2026 (drop netstandard2.0). Not another 5.x.