Repository navigation
Setup NuGet Trusted Publisher - #43
Merged
Merged
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
jnm2
approved these changes
Aug 31, 2026
Collaborator
|
@buvinghausen Dropping net8 and net9 from the package and replacing with net10 is also okay with me because 8 and 9 are EOL mid-November. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
@jnm2 it's that time of year for the annual housekeeping with .NET 11 dropping in November and .NET 8 and .NET 9 rolling off support. I know you are hyper opinionated on which tfm you want the package to support so let me know if you want any changes and I'll make them. If not just approve and merge and then the next CI release will go out using the new trusted profile..
Summary
Ports NuGet publishing to Trusted Publishing (OIDC). Also trims the
CI matrix to the TFMs actually under test and bumps the pinned actions.
NuGet Trusted Publisher
release.ymlno longer carries a long-lived API key. The job requests an OIDC token(
permissions: id-token: write),NuGet/login@v1exchanges it for a short-lived nuget.orgkey, and
dotnet nuget pushuses that. The trust policy lives on nuget.org; the repo onlyneeds the
NUGET_TRUSTED_PUBLISHER_USERActions variable (set tobuvinghausen, alreadyconfigured on this repo).
The now-unreferenced
nuget_api_keyrepo secret has been deleted.CI matrix
setup-dotnetno longer downloads the .NET 8 and .NET 9 SDKs — only10.0.*/11.0.*.tests/unit/Directory.Build.props) targetnet11.0;net10.0;net472(was
net11.0;net10.0;net9.0;net8.0;net472). The library still multi-targetsnetstandard2.0;net462;net8.0;net9.0for consumers — those legs are simply no longertest-executed, rather than relying on whatever runtimes the hosted image happens to ship.
net11.0project with<Features>runtime-async=on</Features>,so the two per-TFM CI steps collapse into one (plus an explicit
$LASTEXITCODEguard.runtime-async=onremains conditional onnet11.0inTaskTupleAwaiter.Tests.csproj,since that project is still multi-targeted.
test.shandCLAUDE.mdupdated to match the new TFM lists.Action bumps
actions/checkout@v6→@v7,actions/setup-dotnet@v5→@v6, in bothci.ymlandrelease.yml.Verification
./test.sh— net11.0 483 passed, net10.0 483 passed, net472 499 passed (Mono), 0 failed.