diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index cc79dbc..4579df4 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -1,59 +1,65 @@ -name: Publish NuGet Package - -on: - workflow_dispatch: - inputs: - version: - description: Optional package version; defaults to the release tag or project version - required: false - type: string - release: - types: [published] - -concurrency: - group: publish-nuget - cancel-in-progress: false - -env: - DOTNET_CLI_TELEMETRY_OPTOUT: 1 - DOTNET_NOLOGO: true - NUGET_DIRECTORY: ${{ github.workspace }}/artifacts/packages - +name: Publish NuGet Package + +on: + workflow_dispatch: + inputs: + version: + description: Optional package version; defaults to the release tag or project version + required: false + type: string + release: + types: [published] + +concurrency: + group: publish-nuget + cancel-in-progress: false + +env: + DOTNET_CLI_TELEMETRY_OPTOUT: 1 + DOTNET_NOLOGO: true + NUGET_DIRECTORY: ${{ github.workspace }}/artifacts/packages + permissions: contents: read - -jobs: - publish: - runs-on: ubuntu-latest - timeout-minutes: 25 - steps: - - name: Checkout code - uses: actions/checkout@v4 + id-token: write + +jobs: + publish: + runs-on: ubuntu-latest + timeout-minutes: 25 + steps: + - name: Checkout code + uses: actions/checkout@v4 + with: + persist-credentials: false + - name: Setup .NET + uses: actions/setup-dotnet@v4 + with: + dotnet-version: 10.0.x + - name: Restore dependencies + run: dotnet restore src/ToastUIEditor/ToastUIEditor.csproj + - name: Pack + shell: bash + env: + RELEASE_VERSION: ${{ github.event.release.tag_name || inputs.version }} + run: | + version="${RELEASE_VERSION#v}" + args=(src/ToastUIEditor/ToastUIEditor.csproj --configuration Release --no-restore --output "$NUGET_DIRECTORY" -p:ContinuousIntegrationBuild=true) + if [ -n "$version" ]; then args+=("-p:Version=$version"); fi + dotnet pack "${args[@]}" + - name: NuGet login (OIDC to temporary API key) + uses: NuGet/login@v1 + id: nuget-login with: - persist-credentials: false - - name: Setup .NET - uses: actions/setup-dotnet@v4 - with: - dotnet-version: 10.0.x - - name: Restore dependencies - run: dotnet restore src/ToastUIEditor/ToastUIEditor.csproj - - name: Pack - shell: bash - env: - RELEASE_VERSION: ${{ github.event.release.tag_name || inputs.version }} - run: | - version="${RELEASE_VERSION#v}" - args=(src/ToastUIEditor/ToastUIEditor.csproj --configuration Release --no-restore --output "$NUGET_DIRECTORY" -p:ContinuousIntegrationBuild=true) - if [ -n "$version" ]; then args+=("-p:Version=$version"); fi - dotnet pack "${args[@]}" + user: ${{ secrets.NUGET_USER }} - name: Publish to NuGet.org shell: bash - run: | - packages=$(find "$NUGET_DIRECTORY" -maxdepth 1 -name '*.nupkg' ! -name '*.snupkg' -print) - if [ -z "$packages" ]; then - echo "No NuGet package was produced." >&2 - exit 1 - fi - while IFS= read -r package; do - dotnet nuget push "$package" --api-key "${{ secrets.NUGET_API_KEY }}" --source https://api.nuget.org/v3/index.json --skip-duplicate - done <<< "$packages" + run: | + packages=$(find "$NUGET_DIRECTORY" -maxdepth 1 -name '*.nupkg' ! -name '*.snupkg' -print) + if [ -z "$packages" ]; then + echo "No NuGet package was produced." >&2 + exit 1 + fi + while IFS= read -r package; do + dotnet nuget push "$package" --api-key "${{ steps.nuget-login.outputs.NUGET_API_KEY }}" --source https://api.nuget.org/v3/index.json --skip-duplicate + done <<< "$packages"