From bd5dcfe49bd065c47825e6ad9a083bdc07bc565d Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?George=20Guimar=C3=A3es?= Date: Tue, 15 Sep 2026 18:02:22 -0300 Subject: [PATCH] ci: Publish to RubyGems with trusted publishing The API key path cannot publish unattended: the owning account requires an OTP for API pushes, which is why the 2.7.0 and 2.8.0 publish jobs failed. Exchange the job's OIDC token for a RubyGems credential instead, which also lets release-gem attach attestations. --- .github/workflows/release-please.yml | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/.github/workflows/release-please.yml b/.github/workflows/release-please.yml index 4126d78..d093e0a 100644 --- a/.github/workflows/release-please.yml +++ b/.github/workflows/release-please.yml @@ -25,6 +25,13 @@ jobs: needs: release-please if: ${{ needs.release-please.outputs.release_created == 'true' || github.event_name == 'workflow_dispatch' }} runs-on: ubuntu-latest + # Publishes through RubyGems trusted publishing: the job exchanges its + # OIDC token for a short-lived RubyGems credential, so no API key and no + # OTP are involved. The trusted publisher for this repository and workflow + # file is configured on the gem's page at rubygems.org. + permissions: + contents: write + id-token: write steps: - uses: actions/checkout@v4 - uses: ruby/setup-ruby@v1 @@ -34,6 +41,3 @@ jobs: - uses: rubygems/release-gem@v1 with: await-release: false - setup-trusted-publisher: false - env: - GEM_HOST_API_KEY: ${{ secrets.RUBYGEMS_API_KEY }}