Skip to content

Publish to NuGet.org via trusted publishing - #2632

Merged
glopesdev merged 1 commit into
bonsai-rx:mainfrom
glopesdev:trusted-publishing
Jul 6, 2026
Merged

glopesdev merged 1 commit into
bonsai-rx:mainfrom
glopesdev:trusted-publishing

Conversation

@glopesdev

Copy link
Copy Markdown
Member

The NuGet.org publish job authenticated with a long-lived NUGET_API_KEY secret. NuGet.org now recommends trusted publishing, where the workflow exchanges a short-lived GitHub OIDC token for a temporary API key valid for one hour, so there is no long-lived secret to store or rotate. This moves the publish job to that model.

Changes

  • Grant the publish-packages-nuget-org job id-token: write so it can request the OIDC token, alongside contents: read and actions: read for the checkout and artifact-download steps once the permissions block narrows the default token.
  • Add a NuGet/login step that exchanges the OIDC token for a temporary API key immediately before the push.
  • Push with the temporary key instead of NUGET_API_KEY.

A trusted publishing policy is set up on nuget.org for this repository and the Bonsai.yml workflow, scoped to the PublicRelease environment.

The NuGet.org publish job now obtains a short-lived API key through
OIDC trusted publishing, using NuGet/login to exchange a GitHub
id-token for a temporary key, instead of the long-lived NUGET_API_KEY
secret. Adds the id-token write permission to the job and reads the
nuget.org account name from a NUGET_USER secret.
@glopesdev glopesdev added this to the 2.9.1 milestone Jul 6, 2026
@glopesdev
glopesdev requested a review from a team July 6, 2026 14:06
@glopesdev glopesdev added the feature New planned feature label Jul 6, 2026
@glopesdev
glopesdev merged commit d3ba298 into bonsai-rx:main Jul 6, 2026
10 checks passed
@glopesdev
glopesdev deleted the trusted-publishing branch July 6, 2026 15:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

feature New planned feature

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant