Repository navigation
chore: publish to nuget.org via trusted publishing - #878
Conversation
Short-lived OIDC credentials replace the long-lived NuGet API key secret.
There was a problem hiding this comment.
🟢 Approval recommended
The workflow correctly configures and consumes NuGet’s short-lived OIDC credentials.
0 open findings
What changed in this PR
Replaces the long-lived NuGet API key with short-lived OIDC credentials for package publishing.
Changes:
- Grants the publish job OIDC token permission.
- Authenticates through
NuGet/login@v1. - Uses the generated temporary API key when pushing packages.
| File | Description |
|---|---|
.github/workflows/build.yml |
Configures trusted NuGet publishing via OIDC. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
🚀 Benchmark ResultsDetails
Details
Details
Details
Details
Details
|
… publishing (#878) by Valentin Breuß
… publishing (#878) by Valentin Breuß
|
This is addressed in release v3.6.0. |

Short-lived OIDC credentials replace the long-lived NuGet API key secret.