ci(release): NuGet Trusted Publishing (OIDC) instead of a long-lived API key - #33
Merged
Conversation
Commits the lockfile (lockfileVersion 3) so the Tiptap sample builds reproducibly — `npm ci`/`npm install` resolve the exact same dependency tree the sample was verified against, instead of drifting with the caret ranges in package.json. It was previously untracked (generated when the sample was run locally). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Replaces the long-lived NUGET_API_KEY secret with NuGet Trusted Publishing: the publish job requests a GitHub OIDC token (`id-token: write`) and the NuGet/login@v1 action exchanges it for a short-lived (1 h, single-use) API key used by `dotnet nuget push`. No API key to store, rotate, or leak. Requires (operator, one-time): - A trusted-publisher policy on nuget.org: owner = the StrangeDaysTech org, repository owner = StrangeDaysTech, repository = weft, workflow = release.yml, environment = release. - Repo/environment secret NUGET_USER = the nuget.org profile/org username. - The old NUGET_API_KEY secret can be removed. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Switches the
publishjob inrelease.ymlfrom a storedNUGET_API_KEYsecret to NuGet Trusted Publishing (OIDC), per nuget.org's new recommendation for GitHub Actions.What changed
permissions: id-token: writeon the publish job (GitHub OIDC token issuance).NuGet/login@v1exchanges the OIDC token for a short-lived (1 h, single-use) NuGet API key.dotnet nuget pushnow usessteps.nuget-login.outputs.NUGET_API_KEY(temporary) instead ofsecrets.NUGET_API_KEY.No long-lived API key to store, rotate, or leak. The publish stays gated behind
dry_run=false+ thereleaseenvironment.Operator setup (one-time, before the real publish — T060)
StrangeDaysTech; Repository =weft; Workflow File =release.yml; Environment =release.NUGET_USER= the nuget.org profile/org username (not the email).NUGET_API_KEYsecret is no longer needed.🤖 Generated with Claude Code