Publish to NuGet with trusted publishing only - #10
Merged
Merged
Conversation
Trusted publishing works (v12.2.0 was published with it), so the fallback to the NUGET_API_KEY secret is not needed any more. - the login step does not continue on error: a failed login now fails the job before anything is pushed, instead of pushing with an empty or outdated key - the push uses only the short-lived key of the login step The NUGET_API_KEY repository secret is not referenced any more and can be deleted.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Trusted publishing works:
v12.2.0was published with it (OIDC login, run 36209736579). The fallback to theNUGET_API_KEYsecret is not needed any more.Changes (
nuget_deploy.ymlonly)|| secrets.NUGET_API_KEY.continue-on-errorany more. If the login fails, the job fails there, before anything is pushed, instead of pushing with an empty or outdated key and failing later with a less clear error.Nothing else in
.githubreferences a secret, and the documentation does not mention it.After merging
The repository secret
NUGET_API_KEY(last set 2022) is not used any more and can be deleted in the repository settings. This does not have to wait for the merge: the current workflow only uses it as a fallback.Verification
continue-on-error, the job keepsid-token: write