From 5c7fdaad2542020c510a2144b989044da9f8370c Mon Sep 17 00:00:00 2001 From: Zohar Zilberman Date: Thu, 28 May 2026 20:48:35 +0300 Subject: [PATCH] Switch crates.io publishing to OIDC trusted publishing Replace the long-lived CARGO_REGISTRY_TOKEN secret with a short-lived token minted via rust-lang/crates-io-auth-action, removing the need to rotate the token and reducing blast radius if the repo is compromised. --- .github/workflows/release.yml | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index c645412..ddfb292 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -16,12 +16,18 @@ jobs: name: 🚀 Publish to crates.io needs: test runs-on: ubuntu-latest + permissions: + id-token: write steps: - name: 🛠 Checkout uses: actions/checkout@v4 + - name: 🔐 Authenticate to crates.io + uses: rust-lang/crates-io-auth-action@v1 + id: auth + - name: 🚀 Publish Crate env: - CARGO_REGISTRY_TOKEN: ${{ secrets.CARGO_REGISTRY_TOKEN }} + CARGO_REGISTRY_TOKEN: ${{ steps.auth.outputs.token }} run: | cargo publish