Skip to content

Add release workflow with crates.io Trusted Publishing - #60

Closed
dogenkigen wants to merge 1 commit into
mainfrom
claude/crate-release-token-security-de8a26
Closed

dogenkigen wants to merge 1 commit into
mainfrom
claude/crate-release-token-security-de8a26

Conversation

@dogenkigen

Copy link
Copy Markdown
Contributor

Summary

  • Adds .github/workflows/release.yml, which publishes doc-assert to crates.io when a v* tag is pushed.
    • Fails if the tag doesn't match the version in Cargo.toml.
    • Runs the same fmt / clippy / build / test / functional sanity steps as regular CI before publishing.
    • Authenticates via crates.io Trusted Publishing (OIDC, rust-lang/crates-io-auth-action), so no long-lived API token is stored in the repo.
    • Runs in a release GitHub environment so it can be gated with protection rules.
  • Bumps actions/checkout from v3 to v4 in the existing CI workflow.

Required one-time setup (before the first tagged release)

  1. crates.io: doc-assert → Settings → Trusted Publishing → add GitHub publisher: owner DocAssert, repo doc-assert, workflow release.yml, environment release.
  2. GitHub: Settings → Environments → create release; restrict deployment to tags matching v* (optionally require reviewer approval).

Releasing

Bump version in Cargo.toml, merge to main, then:

git tag v0.1.2 && git push origin v0.1.2

🤖 Generated with Claude Code

Publishes the crate when a v* tag is pushed, after verifying the tag
matches the Cargo.toml version and running the full CI suite. Auth uses
OIDC via rust-lang/crates-io-auth-action, so no API token is stored.
Also bumps actions/checkout to v4 in the existing CI workflow.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@dogenkigen dogenkigen closed this Oct 2, 2026
@dogenkigen
dogenkigen deleted the claude/crate-release-token-security-de8a26 branch October 2, 2026 15:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant