From 1cc07987791e919796d3cdd70e60dee329aaf6fc Mon Sep 17 00:00:00 2001 From: Copilot <198982749+Copilot@users.noreply.github.com> Date: Wed, 20 May 2026 17:36:46 +0200 Subject: [PATCH] Use NuGet Trusted Publishing for nuget.org push Agent-Logs-Url: https://github.com/openiddict/openiddict-core/sessions/319b55cd-cf28-46ae-92d5-e34921c69e77 Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: kevinchalet <6998306+kevinchalet@users.noreply.github.com> --- .github/workflows/build.yml | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 935c7215..9428462d 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -166,6 +166,9 @@ jobs: push-packages-nuget: needs: [ build, validate-packages ] runs-on: ubuntu-24.04 + permissions: + contents: read + id-token: write if: | github.event.repository.fork == false && startsWith(github.ref, 'refs/tags/') @@ -180,7 +183,13 @@ jobs: with: dotnet-version: ${{ needs.build.outputs.dotnet-sdk-version }} + - name: Login to NuGet.org (Trusted Publishing) + id: nuget-login + uses: NuGet/login@8d196754b4036150537f80ac539e15c2f1028841 # v1.2.0 + with: + user: ${{ secrets.NUGET_USER }} + - name: Push packages to NuGet.org env: - NUGET_API_KEY: ${{ secrets.NUGET_API_KEY }} + NUGET_API_KEY: ${{ steps.nuget-login.outputs.NUGET_API_KEY }} run: dotnet nuget push "*.nupkg" --api-key "${NUGET_API_KEY}" --skip-duplicate --source https://api.nuget.org/v3/index.json