Skip to content

Commit 1f99f7e

Browse files
committed
Publish to nuget.org with Trusted Publishing instead of a stored API key
The master workflow now requests an OIDC token, exchanges it through NuGet/login for a one-hour API key, and pushes with that. The NugetKey secret is no longer read. The nuget.org policy is bound to this repository and to the workflow file name, so the file keeps its name.
1 parent 1ec9694 commit 1f99f7e

1 file changed

Lines changed: 16 additions & 1 deletion

File tree

‎.github/workflows/build_publish_master.yml‎

Lines changed: 16 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,14 @@ on:
55
- "**/*.md"
66
branches: [ master ]
77

8+
# Publishing uses nuget.org Trusted Publishing: the job requests an OIDC token from GitHub, NuGet/login exchanges
9+
# it for an API key that lives one hour, and the push uses that key. No long-lived NuGet secret is stored here.
10+
# The nuget.org policy is bound to this repository and to this file's name (build_publish_master.yml); renaming
11+
# the file or moving the push to another workflow needs a new policy on nuget.org.
12+
permissions:
13+
id-token: write
14+
contents: read
15+
816
jobs:
917
build:
1018

@@ -28,9 +36,16 @@ jobs:
2836
run: dotnet build AustinHarris.JsonRpc.sln --configuration Release --no-restore
2937
- name: Test
3038
run: dotnet test AustinHarris.JsonRpcTestN --configuration Release --no-build
39+
# The key is requested after the tests so it is fresh for the push (it expires after one hour). `user` is the
40+
# nuget.org profile that owns the packages and the trusted publishing policy.
41+
- name: NuGet login (OIDC to a temporary API key)
42+
uses: NuGet/login@v1
43+
id: nuget-login
44+
with:
45+
user: AustinHarris
3146
# Publish all four packages: the core and the three companions (Json.NET, System.Text.Json, ASP.NET Core).
3247
- name: publish nuget version change
3348
run: |
3449
for project in Json-Rpc AustinHarris.JsonRpc.Newtonsoft AustinHarris.JsonRpc.SystemTextJson AustinHarris.JsonRpc.AspNetCore; do
35-
dotnet nuget push "$project/bin/Release/"*.nupkg --skip-duplicate --source "https://api.nuget.org/v3/index.json" --api-key ${{ secrets.NugetKey }} # API key for the NuGet feed
50+
dotnet nuget push "$project/bin/Release/"*.nupkg --skip-duplicate --source "https://api.nuget.org/v3/index.json" --api-key "${{ steps.nuget-login.outputs.NUGET_API_KEY }}"
3651
done

0 commit comments

Comments
 (0)