Skip to content

Conversation

@tomodachi94
Copy link

This approach eliminates the security risks associated with long-lived write tokens, which can be compromised, accidentally exposed in logs, or require manual rotation. (npmjs.com)

There is still a little bit of manual work you'll need to do before this will work: https://crates.io/docs/trusted-publishing

The CARGO_REGISTRY_TOKEN secret can be deleted after this is merged.

    This approach eliminates the security risks associated with long-lived write tokens, which can be compromised, accidentally exposed in logs, or require manual rotation. (npmjs.com)

There is still a little bit of manual work you'll need to do before this will work:
https://crates.io/docs/trusted-publishing

The `CARGO_REGISTRY_TOKEN` secret can be deleted after this is merged.
@dubadub
Copy link
Member

dubadub commented Jan 11, 2026

Sorry, haven't noticed your PR and added the same d5ea804

@dubadub dubadub closed this Jan 11, 2026
@tomodachi94 tomodachi94 deleted the trusted-publishing branch January 11, 2026 06:43
@tomodachi94
Copy link
Author

No worries!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants