Skip to content

ci: publish to crates.io by OIDC instead of a personal API token - #103

Merged
JosteinGj merged 1 commit into
mainfrom
ci/crates-trusted-publishing
Aug 25, 2026
Merged

ci: publish to crates.io by OIDC instead of a personal API token#103
JosteinGj merged 1 commit into
mainfrom
ci/crates-trusted-publishing

Conversation

@JosteinGj

Copy link
Copy Markdown
Contributor

The PyPI half of the release already authenticates as this repository; the crates.io half authenticated as whoever created CARGO_REGISTRY_TOKEN. That made one person a single point of failure independent of who owns the crate — the token outlives their involvement, or dies with their account, and no amount of adding owners changes it.

crates-io-auth-action exchanges the run's OIDC identity for a token scoped to this crate and revokes it in its post step, so the credential exists only for the length of the job and there is no secret to rotate. The pairing now matches PyPI's on both sides of the release.

Merging this before registering the Trusted Publisher on crates.io breaks the next release at the auth step, so register it first; the setup needs a crate that already has a published version, which is why this follows 0.2.0 rather than shipping with it.

The PyPI half of the release already authenticates as this repository; the crates.io half
authenticated as whoever created `CARGO_REGISTRY_TOKEN`. That made one person a single point of
failure independent of who owns the crate — the token outlives their involvement, or dies with
their account, and no amount of adding owners changes it.

`crates-io-auth-action` exchanges the run's OIDC identity for a token scoped to this crate and
revokes it in its post step, so the credential exists only for the length of the job and there is
no secret to rotate. The pairing now matches PyPI's on both sides of the release.

Merging this before registering the Trusted Publisher on crates.io breaks the next release at the
auth step, so register it first; the setup needs a crate that already has a published version,
which is why this follows 0.2.0 rather than shipping with it.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@JosteinGj
JosteinGj merged commit 201f2ca into main Aug 25, 2026
34 checks passed
@JosteinGj
JosteinGj deleted the ci/crates-trusted-publishing branch August 25, 2026 06:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant