Skip to content

ci: use NuGet OIDC trusted publishing instead of a long-lived API key - #13

Merged
johnkors merged 3 commits into
mainfrom
jk/nuget-oidc-trusted-publishing
Sep 21, 2026
Merged

johnkors merged 3 commits into
mainfrom
jk/nuget-oidc-trusted-publishing

Conversation

@johnkors

@johnkors johnkors commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor
  • Release.yml and PreRelease.yml consolidated into one Release.yml with a prerelease workflow_dispatch input, same shape as Slackbot.Net's - one workflow to run instead of two near-duplicates
  • Publishing now exchanges GitHub's OIDC token for a short-lived NuGet API key via NuGet/login, same pattern as Slackbot.Net's Release.yml
  • Needs a Trusted Publisher policy on nuget.org for this package pointing at dotnetbots/CronBackgroundServices (workflow file Release.yml) before this can actually publish - the NUGET_USER secret is already set
  • Adds an empty commit tagging the next release as a major version bump (+semver: major) - the already-merged scoped-recurring-actions change (Make recurring actions scoped instead of singleton #12) is breaking (GetServices() no longer resolves anything) but its commit message didn't carry the marker, so GitVersion would otherwise have shipped it as a patch/minor

Same pattern as Slackbot.Net's Release.yml: NuGet/login exchanges GitHub's
OIDC token for a short-lived NuGet API key at publish time, so NUGETORGAPIKEY
no longer needs to be stored as a long-lived secret.
…e toggle

Same shape as Slackbot.Net's Release.yml: a single workflow_dispatch input
picks the version scheme, and the GitHub release step is skipped for
prereleases - one workflow to run instead of two near-duplicates.
+semver: major

AddRecurrer<T>'s move from singleton to scoped registration (#12) breaks
any consumer holding a reference to a recurring action expecting it to
stay the same instance across ticks, or calling
GetServices<IRecurringAction>() (no longer registered as an open
multi-service - only the concrete T is). GitVersion's +semver: major
convention (no explicit config override in this repo, so its default
regex applies) picks this up for the next release.
@johnkors
johnkors merged commit 9242962 into main Sep 21, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant