Repository navigation
ci: publish to nuget.org via Trusted Publishing (OIDC) - #147
Merged
Merged
Conversation
Replace the long-lived NUGET_SECRET_KEY org secret with nuget.org Trusted Publishing: the publish job gets id-token: write and exchanges its GitHub OIDC token for a short-lived (1h) NuGet API key via NuGet/login@v1 (user: microtingas) right before the push. nuget.org API keys created before 2026-08-17 stop working on 2026-11-01, so the old secret would break publishing anyway. Requires a matching Trusted Publishing policy on nuget.org (owner microting, this repo, this workflow file) before merging. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
The required nuget.org Trusted Publishing policy must be confirmed before merging.
Review effort: Balanced
Findings: None
What changed in this PR
Migrates NuGet release publishing from a long-lived secret to OIDC-based Trusted Publishing.
Changes:
- Grants the deploy job OIDC token permission.
- Uses
NuGet/login@v1to obtain a temporary API key for both package pushes.
| File | Description |
|---|---|
.github/workflows/dotnet-release.yml |
Replaces secret-based NuGet authentication with Trusted Publishing. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
.github/workflows/dotnet-release.yml: the nuget.org publish job no longer uses the long-livedNUGET_SECRET_KEYorg secret. Instead it uses nuget.org Trusted Publishing:permissions: id-token: write(pluscontents: read)NuGet/login@v1step (user:microtingas) exchanges the GitHub OIDC token for a short-lived (1h) NuGet API key right before the pushdotnet nuget pushuses that temporary key instead ofsecrets.NUGET_SECRET_KEYWhy
nuget.org API keys created before 2026-08-17 stop working on 2026-11-01, so the current secret would break publishing anyway. Trusted Publishing removes the long-lived key entirely.
microtingasmicrotingRebusdotnet-release.ymlMicroting.Rebus,Microting.Rebus.Tests.ContractsTest plan
v*.*.*tag release publishes via OIDCNUGET_SECRET_KEYuntil verified🤖 Generated with Claude Code