Publish to NuGet.org via trusted publishing - #2632
Merged
Merged
Conversation
The NuGet.org publish job now obtains a short-lived API key through OIDC trusted publishing, using NuGet/login to exchange a GitHub id-token for a temporary key, instead of the long-lived NUGET_API_KEY secret. Adds the id-token write permission to the job and reads the nuget.org account name from a NUGET_USER secret.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The NuGet.org publish job authenticated with a long-lived NUGET_API_KEY secret. NuGet.org now recommends trusted publishing, where the workflow exchanges a short-lived GitHub OIDC token for a temporary API key valid for one hour, so there is no long-lived secret to store or rotate. This moves the publish job to that model.
Changes
publish-packages-nuget-orgjobid-token: writeso it can request the OIDC token, alongsidecontents: readandactions: readfor the checkout and artifact-download steps once the permissions block narrows the default token.NuGet/loginstep that exchanges the OIDC token for a temporary API key immediately before the push.NUGET_API_KEY.A trusted publishing policy is set up on nuget.org for this repository and the
Bonsai.ymlworkflow, scoped to thePublicReleaseenvironment.