Skip to content

Switch crates.io publishing to OIDC trusted publishing - #15

Merged
popen2 merged 1 commit into
mainfrom
switch-to-trusted-publishing
May 28, 2026
Merged

popen2 merged 1 commit into
mainfrom
switch-to-trusted-publishing

Conversation

@popen2

@popen2 popen2 commented May 28, 2026

Copy link
Copy Markdown
Member

Summary

  • Replace the long-lived CARGO_REGISTRY_TOKEN secret with a short-lived token minted via rust-lang/crates-io-auth-action.
  • Grant the publish job id-token: write so it can request a GitHub OIDC token to exchange with crates.io.

Follow-up (post-merge)

  1. Configure the Trusted Publisher on crates.io for this crate:
    • Repository owner: platzio
    • Repository name: chart-ext
    • Workflow filename: release.yml
    • Environment: (none)
  2. After the first successful release via trusted publishing, delete the CARGO_REGISTRY_TOKEN repo secret and revoke the corresponding token on crates.io.

Test plan

  • Configure the trusted publisher on crates.io before the next tag push.
  • Push a release tag and confirm the 🚀 Publish to crates.io job authenticates and publishes successfully.

Replace the long-lived CARGO_REGISTRY_TOKEN secret with a short-lived
token minted via rust-lang/crates-io-auth-action, removing the need to
rotate the token and reducing blast radius if the repo is compromised.
@popen2
popen2 merged commit 2155696 into main May 28, 2026
3 checks passed
@popen2
popen2 deleted the switch-to-trusted-publishing branch May 28, 2026 17:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant