Skip to content

Migrate NuGet publish to trusted publishing (OIDC) - #92

Merged
Redth merged 1 commit into
mainfrom
redth/nuget-trusted-publishing
Mar 31, 2026
Merged

Redth merged 1 commit into
mainfrom
redth/nuget-trusted-publishing

Conversation

@Redth

@Redth Redth commented Mar 31, 2026

Copy link
Copy Markdown
Owner

Why

The publish workflow currently uses a long-lived NUGET_ORG_API_KEY secret to push packages to nuget.org. NuGet now supports trusted publishing via OIDC, which eliminates the need to manage and rotate API keys — the workflow exchanges a short-lived GitHub Actions OIDC token for a NuGet push token at publish time.

What changed

The publish job in build-publish.yml is updated to use OIDC-based auth:

  • environment: release — scopes secrets and enables optional approval gates
  • permissions: id-token: write — required for the OIDC token request
  • NuGet/login@v1 — exchanges the OIDC token for a NuGet API key
  • --skip-duplicate — makes pushes idempotent for safe re-runs

The build job and package matrix are unchanged.

Manual setup required

Before merging, these one-time steps are needed:

  1. Create a GitHub Environment named release in Settings → Environments with a secret NUGET_USER set to the nuget.org profile username
  2. Create trusted publishing policies at nuget.org/account/trustedpublishing for each package (AndroidSdk.Tool, AndroidSdk, AndroidSdk.Adbd, AndroidRepository) with workflow = build-publish.yml, environment = release
  3. After a successful publish, delete the old NUGET_ORG_API_KEY repo secret

Replace long-lived NUGET_ORG_API_KEY secret with OIDC-based
NuGet/login@v1 for keyless publishing. Adds:
- environment: release (for secret scoping + approval gates)
- permissions: id-token: write (required for OIDC)
- NuGet/login@v1 step for token exchange
- --skip-duplicate flag for idempotent pushes

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@Redth
Redth merged commit 853156f into main Mar 31, 2026
4 of 6 checks passed
@Redth
Redth deleted the redth/nuget-trusted-publishing branch March 31, 2026 15:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant