Skip to content

Conversation

@martincostello
Copy link
Owner

@martincostello martincostello commented Sep 11, 2025

Switch to using GitHub OIDC for pushing packages to NuGet.org with Trusted Publishing.

Switch to using GitHub OIDC for pushing packages to NuGet.org with Trusted Publishing.
@martincostello martincostello added enhancement New feature or request dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code .NET Pull requests that update .net code labels Sep 11, 2025
@codecov
Copy link

codecov bot commented Sep 11, 2025

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 98.59%. Comparing base (8845dcd) to head (12ca4bf).
⚠️ Report is 7 commits behind head on main.
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #1019   +/-   ##
=======================================
  Coverage   98.59%   98.59%           
=======================================
  Files          16       16           
  Lines         284      284           
  Branches       37       37           
=======================================
  Hits          280      280           
  Misses          2        2           
  Partials        2        2           
Flag Coverage Δ
linux 98.59% <ø> (ø)
macos 98.59% <ø> (+0.70%) ⬆️
windows 98.59% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

Update NuGet/login action to v1.1.0.
Copilot AI review requested due to automatic review settings September 18, 2025 09:48
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR migrates the NuGet package publishing workflow from API key authentication to GitHub OIDC Trusted Publishing for enhanced security.

  • Adds OIDC token permissions and NuGet login action for trusted publishing
  • Replaces static API key secret with dynamically generated token from login step
  • Maintains existing package publishing logic while improving authentication security

Tip: Customize your code reviews with copilot-instructions.md. Create the file or learn how to get started.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file enhancement New feature or request github_actions Pull requests that update GitHub Actions code .NET Pull requests that update .net code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants