Skip to content

ci: publish to NuGet with trusted publishing - #105

Merged
ChiragAgg5k merged 2 commits into
mainfrom
ci/nuget-trusted-publishing
Oct 6, 2026
Merged

ChiragAgg5k merged 2 commits into
mainfrom
ci/nuget-trusted-publishing

Conversation

@ChiragAgg5k

@ChiragAgg5k ChiragAgg5k commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

Switches the NuGet publish to trusted publishing: NuGet/login (pinned to v1.2.0) exchanges the job's GitHub OIDC token for a one-hour NuGet API key, so no long-lived NUGET_TOKEN is stored. The old key expired, which is why the 8.1.0 publish failed with 403.

  • job permissions: contents: read, id-token: write
  • NuGet/login step, user from the NUGET_USER repository variable (the nuget.org profile name, not an email; it only names the account the key is issued for, so it is not a secret)
  • dotnet nuget push uses steps.login.outputs.NUGET_API_KEY

Before the next release, on nuget.org (signed in as a member of the Appwrite account that owns the package): Trusted Publishing → add a policy owned by Appwrite with Repository Owner appwrite, Repository sdk-for-dotnet, Workflow File publish.yml, no environment. Then set the NUGET_USER repository variable. Both are done.

Related: appwrite/sdk-generator#1975

The NUGET_TOKEN API key expired, so 8.1.0 failed to publish with 403. NuGet/login exchanges the job's GitHub OIDC token for a one-hour API key, so no long-lived key is stored.
It only names the nuget.org account the short-lived key is issued for and grants nothing on its own.
@hansi-codes

hansi-codes Bot commented Oct 6, 2026

Copy link
Copy Markdown

🟢 Tier S · Ready to merge

No concrete defects were found in the workflow changes or their integration with the existing package build.

The release workflow switches NuGet authentication from a stored API key to trusted publishing. It grants the job OIDC access, adds a pinned NuGet login action using the repository’s NUGET_USER variable, and passes the resulting short-lived key to the existing publish command.

Verdict New comments Fixed Still open
✅ Approved 0 0 0
📂 Walkthrough · 1
File Change
.github/workflows/publish.yml Adds OIDC permissions and NuGet login, replacing the stored publishing secret with the login action’s short-lived API key.

Reviewed d9d1db0 · Details · Comment @hansi-codes review to re-run, or mention @hansi-codes with a question.

@hansi-codes hansi-codes Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Tier S · Looks good to merge. Summary

@ChiragAgg5k
ChiragAgg5k merged commit 60d6ca5 into main Oct 6, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant