From 347eba897a3b49eb81dd0194f7ed311a43e1b932 Mon Sep 17 00:00:00 2001 From: Benziza Date: Thu, 17 Sep 2026 21:38:36 +0200 Subject: [PATCH] ci: publish NuGet tool with trusted publishing --- .github/workflows/publish-nuget.yml | 15 ++++++++------- docs/RELEASING.md | 7 +++---- 2 files changed, 11 insertions(+), 11 deletions(-) diff --git a/.github/workflows/publish-nuget.yml b/.github/workflows/publish-nuget.yml index ca12b64..3c59bc4 100644 --- a/.github/workflows/publish-nuget.yml +++ b/.github/workflows/publish-nuget.yml @@ -5,6 +5,7 @@ on: permissions: contents: read + id-token: write concurrency: group: nuget-publish @@ -21,12 +22,12 @@ jobs: dotnet-version: '10.0.4xx' - run: dotnet test WhyConfig.slnx -c Release - run: dotnet pack src/WhyConfig.Cli/WhyConfig.Cli.csproj -c Release --no-restore -o artifacts + - name: Sign in to NuGet.org + id: login + uses: NuGet/login@v1 + with: + user: Benziza - name: Publish to NuGet.org env: - NUGET_API_KEY: ${{ secrets.NUGET_API_KEY }} - run: | - if [ -z "$NUGET_API_KEY" ]; then - echo "Set the NUGET_API_KEY repository secret before publishing." >&2 - exit 1 - fi - dotnet nuget push artifacts/WhyConfig.NET.*.nupkg --source https://api.nuget.org/v3/index.json + NUGET_API_KEY: ${{ steps.login.outputs.NUGET_API_KEY }} + run: dotnet nuget push artifacts/WhyConfig.NET.*.nupkg --source https://api.nuget.org/v3/index.json diff --git a/docs/RELEASING.md b/docs/RELEASING.md index 88538c2..1c7f2bf 100644 --- a/docs/RELEASING.md +++ b/docs/RELEASING.md @@ -2,9 +2,8 @@ The GitHub repository can stay private while the tool package is public on NuGet.org. -1. Sign in to the [Benziza NuGet.org account](https://www.nuget.org/profiles/Benziza) and create a [Push API key](https://learn.microsoft.com/en-us/nuget/nuget-org/publish-a-package#create-an-api-key). For the first release, allow new packages in the key's package scope. -2. Save the key as the `NUGET_API_KEY` secret in this repository's **Settings → Secrets and variables → Actions**. Do not commit the key. -3. Run the **Publish NuGet tool** workflow from `main` in the Actions tab. -4. After NuGet.org lists the package, verify installation with `dotnet tool install --global WhyConfig.NET` and `whyconfig --help`. +1. In the [Benziza NuGet.org account](https://www.nuget.org/profiles/Benziza), create a [Trusted Publishing policy](https://learn.microsoft.com/en-us/nuget/nuget-org/trusted-publishing) with package owner `Benziza`, repository owner `Benziza`, repository `WhyConfig.NET`, workflow file `publish-nuget.yml`, no environment, and package glob `WhyConfig.NET`. Allow publishing new packages and new versions. +2. Run the **Publish NuGet tool** workflow from `main` in the Actions tab. It uses GitHub OIDC to obtain a short-lived publishing credential; no API key secret is needed. +3. After NuGet.org lists the package, verify installation with `dotnet tool install --global WhyConfig.NET` and `whyconfig --help`. For another release, change `Version` in `src/WhyConfig.Cli/WhyConfig.Cli.csproj`, merge it, then run the workflow again. NuGet.org does not allow replacing a published package version.