Skip to content

ci: publish to nuget.org via Trusted Publishing (OIDC) - #147

Merged
renemadsen merged 1 commit into
masterfrom
ci/nuget-trusted-publishing
Oct 6, 2026
Merged

renemadsen merged 1 commit into
masterfrom
ci/nuget-trusted-publishing

Conversation

@renemadsen

Copy link
Copy Markdown
Member

What changed

.github/workflows/dotnet-release.yml: the nuget.org publish job no longer uses the long-lived NUGET_SECRET_KEY org secret. Instead it uses nuget.org Trusted Publishing:

  • the publish job gets permissions: id-token: write (plus contents: read)
  • a NuGet/login@v1 step (user: microtingas) exchanges the GitHub OIDC token for a short-lived (1h) NuGet API key right before the push
  • dotnet nuget push uses that temporary key instead of secrets.NUGET_SECRET_KEY

Why

nuget.org API keys created before 2026-08-17 stop working on 2026-11-01, so the current secret would break publishing anyway. Trusted Publishing removes the long-lived key entirely.

⚠️ Do not merge until the nuget.org Trusted Publishing policy for this repo/workflow exists

  • Policy owner: microtingas
  • Repository owner: microting
  • Repository: Rebus
  • Workflow: dotnet-release.yml
  • Package scope: Microting.Rebus, Microting.Rebus.Tests.Contracts

Test plan

  • Next v*.*.* tag release publishes via OIDC
  • Keep NUGET_SECRET_KEY until verified

🤖 Generated with Claude Code

Replace the long-lived NUGET_SECRET_KEY org secret with nuget.org
Trusted Publishing: the publish job gets id-token: write and exchanges
its GitHub OIDC token for a short-lived (1h) NuGet API key via
NuGet/login@v1 (user: microtingas) right before the push.

nuget.org API keys created before 2026-08-17 stop working on
2026-11-01, so the old secret would break publishing anyway.

Requires a matching Trusted Publishing policy on nuget.org
(owner microting, this repo, this workflow file) before merging.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Copilot AI balanced review requested due to automatic review settings October 6, 2026 06:32

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The required nuget.org Trusted Publishing policy must be confirmed before merging.

Review effort: Balanced
Findings: None

What changed in this PR

Migrates NuGet release publishing from a long-lived secret to OIDC-based Trusted Publishing.

Changes:

  • Grants the deploy job OIDC token permission.
  • Uses NuGet/login@v1 to obtain a temporary API key for both package pushes.
File Description
.github/​workflows/​dotnet-release.yml Replaces secret-based NuGet authentication with Trusted Publishing.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@renemadsen
renemadsen merged commit ad0752e into master Oct 6, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants