Skip to content

Commit 9899f5a

Browse files
committed
trusted publish
1 parent fff6b01 commit 9899f5a

1 file changed

Lines changed: 11 additions & 1 deletion

File tree

‎.github/workflows/release.yml‎

Lines changed: 11 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -55,6 +55,10 @@ jobs:
5555
runs-on: ubuntu-22.04
5656
needs: release
5757
environment: release
58+
permissions:
59+
# Required for crates.io Trusted Publishing (OIDC).
60+
contents: read
61+
id-token: write
5862
steps:
5963
- uses: actions/checkout@v4
6064

@@ -72,6 +76,12 @@ jobs:
7276
with:
7377
python-version: '3.x'
7478

79+
# Exchange the GitHub OIDC token for a short-lived crates.io token.
80+
# Sets CARGO_REGISTRY_TOKEN in the environment for subsequent steps.
81+
- name: Authenticate to crates.io (Trusted Publishing)
82+
uses: rust-lang/crates-io-auth-action@v1
83+
id: auth
84+
7585
# Skip if this version is already on crates.io so re-running the
7686
# workflow (or moving the tag) doesn't fail on a duplicate publish.
7787
- name: Publish to crates.io
@@ -84,7 +94,7 @@ jobs:
8494
cargo publish
8595
fi
8696
env:
87-
CARGO_REGISTRY_TOKEN: ${{ secrets.CRATES_IO_TOKEN }}
97+
CARGO_REGISTRY_TOKEN: ${{ steps.auth.outputs.token }}
8898

8999
publish-npm:
90100
name: Publish to npm

0 commit comments

Comments
 (0)