Skip to content

ci(release): publish via OIDC trusted publishing - #41

Merged
ronaldtse merged 1 commit into
mainfrom
ci/oidc-trusted-publishing
Aug 18, 2026
Merged

ronaldtse merged 1 commit into
mainfrom
ci/oidc-trusted-publishing

Conversation

@ronaldtse

Copy link
Copy Markdown
Contributor

Summary

  • Replaces the API-key credentials-file publish step with OIDC trusted publishing: rubygems/configure-rubygems-credentials (v2.1.0, pinned) exchanges the job's OIDC token for a short-lived key; id-token: write is already in the permissions block.
  • Also drops the stray no-arg gem signin and mkdir tmp from the publish step.
  • The gem's trusted publisher (fontist/ffi-libarchive-binary @ release.yml) is configured on rubygems.org; the removed FONTIST_CI_RUBYGEMS_API_KEY org secret means the old path would have failed with empty credentials.

Test plan

  • YAML parses.
  • After merge: a skip-mode dispatch exercises the exchange with no new version.

The FONTIST_CI_RUBYGEMS_API_KEY org secret was removed in the migration
to trusted publishing, so the credentials-file heredoc (plus the no-arg
gem signin) would write empty credentials and fail. Exchange the job's
OIDC token for a short-lived API key with
rubygems/configure-rubygems-credentials instead; id-token: write is
already granted. The gem's trusted publisher
(fontist/ffi-libarchive-binary @ release.yml) is configured on
rubygems.org.
@ronaldtse
ronaldtse merged commit a966210 into main Aug 18, 2026
29 of 30 checks passed
@ronaldtse
ronaldtse deleted the ci/oidc-trusted-publishing branch August 18, 2026 08:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant