-
-
Notifications
You must be signed in to change notification settings - Fork 14
Use NuGet Trusted Publishing #1019
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
Switch to using GitHub OIDC for pushing packages to NuGet.org with Trusted Publishing.
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #1019 +/- ##
=======================================
Coverage 98.59% 98.59%
=======================================
Files 16 16
Lines 284 284
Branches 37 37
=======================================
Hits 280 280
Misses 2 2
Partials 2 2
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Sentry. |
Update NuGet/login action to v1.1.0.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Pull Request Overview
This PR migrates the NuGet package publishing workflow from API key authentication to GitHub OIDC Trusted Publishing for enhanced security.
- Adds OIDC token permissions and NuGet login action for trusted publishing
- Replaces static API key secret with dynamically generated token from login step
- Maintains existing package publishing logic while improving authentication security
Tip: Customize your code reviews with copilot-instructions.md. Create the file or learn how to get started.
Switch to using GitHub OIDC for pushing packages to NuGet.org with Trusted Publishing.