Skip to content

Setup NuGet Trusted Publisher - #43

Merged
buvinghausen merged 1 commit into
masterfrom
trusted_publisher
Aug 31, 2026
Merged

buvinghausen merged 1 commit into
masterfrom
trusted_publisher

Conversation

@buvinghausen

Copy link
Copy Markdown
Owner

@jnm2 it's that time of year for the annual housekeeping with .NET 11 dropping in November and .NET 8 and .NET 9 rolling off support. I know you are hyper opinionated on which tfm you want the package to support so let me know if you want any changes and I'll make them. If not just approve and merge and then the next CI release will go out using the new trusted profile..

image

Summary

Ports NuGet publishing to Trusted Publishing (OIDC). Also trims the
CI matrix to the TFMs actually under test and bumps the pinned actions.

NuGet Trusted Publisher

release.yml no longer carries a long-lived API key. The job requests an OIDC token
(permissions: id-token: write), NuGet/login@v1 exchanges it for a short-lived nuget.org
key, and dotnet nuget push uses that. The trust policy lives on nuget.org; the repo only
needs the NUGET_TRUSTED_PUBLISHER_USER Actions variable (set to buvinghausen, already
configured on this repo).

+    permissions:
+      contents: read
+      id-token: write
...
+    - name: NuGet login (OIDC -> temp API key)
+      uses: NuGet/login@v1
+      id: login
+      with:
+        user: ${{ vars.NUGET_TRUSTED_PUBLISHER_USER }}
     - name: Publish NuGet Package
-      run: dotnet nuget push *.nupkg --api-key ${{ secrets.nuget_api_key }} ...
+      run: dotnet nuget push *.nupkg --api-key ${{ steps.login.outputs.NUGET_API_KEY }} ...

The now-unreferenced nuget_api_key repo secret has been deleted.

CI matrix

  • setup-dotnet no longer downloads the .NET 8 and .NET 9 SDKs — only 10.0.* / 11.0.*.
  • Unit tests (tests/unit/Directory.Build.props) target net11.0;net10.0;net472
    (was net11.0;net10.0;net9.0;net8.0;net472). The library still multi-targets
    netstandard2.0;net462;net8.0;net9.0 for consumers — those legs are simply no longer
    test-executed, rather than relying on whatever runtimes the hosted image happens to ship.
  • The AOT smoke test is now a single-TFM net11.0 project with <Features>runtime-async=on</Features>,
    so the two per-TFM CI steps collapse into one (plus an explicit $LASTEXITCODE guard.
  • runtime-async=on remains conditional on net11.0 in TaskTupleAwaiter.Tests.csproj,
    since that project is still multi-targeted.
  • test.sh and CLAUDE.md updated to match the new TFM lists.

Action bumps

actions/checkout@v6 → @v7, actions/setup-dotnet@v5 → @v6, in both ci.yml and release.yml.

Verification

  • ./test.sh — net11.0 483 passed, net10.0 483 passed, net472 499 passed (Mono), 0 failed.
  • AOT publish of the smoke test built native and ran clean, exit 0:
    arity-1 typed: 1
    arity-2 typed CA(false): 2, two
    arity-2 typed CA(options): 3, three
    arity-16 typed: 1..16 (sum check: 136)
    non-generic arity-2: ok
    non-generic arity-2 CA(options): ok
    AOT smoke-test completed.
    

@buvinghausen
buvinghausen requested a review from jnm2 August 31, 2026 22:59
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Aug 31, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-08-31T23:02:07.655655Z 770a9c4 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@buvinghausen
buvinghausen merged commit 9242b97 into master Aug 31, 2026
1 check passed
@buvinghausen
buvinghausen deleted the trusted_publisher branch August 31, 2026 23:08
@jnm2

jnm2 commented Sep 5, 2026

Copy link
Copy Markdown
Collaborator

@buvinghausen Dropping net8 and net9 from the package and replacing with net10 is also okay with me because 8 and 9 are EOL mid-November.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants