diff --git a/.github/workflows/release-please.yml b/.github/workflows/release-please.yml index 4126d78..d093e0a 100644 --- a/.github/workflows/release-please.yml +++ b/.github/workflows/release-please.yml @@ -25,6 +25,13 @@ jobs: needs: release-please if: ${{ needs.release-please.outputs.release_created == 'true' || github.event_name == 'workflow_dispatch' }} runs-on: ubuntu-latest + # Publishes through RubyGems trusted publishing: the job exchanges its + # OIDC token for a short-lived RubyGems credential, so no API key and no + # OTP are involved. The trusted publisher for this repository and workflow + # file is configured on the gem's page at rubygems.org. + permissions: + contents: write + id-token: write steps: - uses: actions/checkout@v4 - uses: ruby/setup-ruby@v1 @@ -34,6 +41,3 @@ jobs: - uses: rubygems/release-gem@v1 with: await-release: false - setup-trusted-publisher: false - env: - GEM_HOST_API_KEY: ${{ secrets.RUBYGEMS_API_KEY }}