-
-
Notifications
You must be signed in to change notification settings - Fork 177
feat(actions): add nuget trusted publishing #1277
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
feat(actions): add nuget trusted publishing #1277
Conversation
|
Note: I think leaving NuGet/login without a SHA hash is fine since it's an official Microsoft action.
|
If you know how to configure renovate to share that policy, I'd welcome that. :) |
AArnott
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks!
Updated [nbgv](https://github.com/dotnet/Nerdbank.GitVersioning) from 3.8.118 to 3.9.50. <details> <summary>Release notes</summary> _Sourced from [nbgv's releases](https://github.com/dotnet/Nerdbank.GitVersioning/releases)._ ## 3.9.50 ## What's Changed * Add `versionHeightOffsetAppliesTo` property to version.json by @Copilot in dotnet/Nerdbank.GitVersioning#1279 * Fix `nbgv prepare-release` command to honor inheriting version.json files by @AArnott in dotnet/Nerdbank.GitVersioning#1281 * Automatically disable git engine for Dependabot environments by @Copilot in dotnet/Nerdbank.GitVersioning#1284 * Add --what-if switch to nbgv tag command to preview tag names by @Copilot in dotnet/Nerdbank.GitVersioning#1287 * Auto-disable git engine for GitHub Copilot environments by @Copilot in dotnet/Nerdbank.GitVersioning#1291 * Allow uppercase letters in pre-release version identifiers by @Copilot in dotnet/Nerdbank.GitVersioning#1293 ## New Contributors * @micheloliveira-com made their first contribution in dotnet/Nerdbank.GitVersioning#1277 **Full Changelog**: dotnet/Nerdbank.GitVersioning@v3.8.118...v3.9.50 ## 3.9.37-alpha ## What's Changed * Auto-disable git engine for GitHub Copilot environments by @Copilot in dotnet/Nerdbank.GitVersioning#1291 **Full Changelog**: dotnet/Nerdbank.GitVersioning@v3.9.32-alpha...v3.9.37-alpha ## 3.9.32-alpha ## What's Changed * Automatically disable git engine for Dependabot environments by @Copilot in dotnet/Nerdbank.GitVersioning#1284 * Add --what-if switch to nbgv tag command to preview tag names by @Copilot in dotnet/Nerdbank.GitVersioning#1287 **Full Changelog**: dotnet/Nerdbank.GitVersioning@v3.9.17-alpha...v3.9.32-alpha ## 3.9.17-alpha ## What's Changed * Fix `nbgv prepare-release` command to honor inheriting version.json files by @AArnott in dotnet/Nerdbank.GitVersioning#1281 **Full Changelog**: dotnet/Nerdbank.GitVersioning@v3.9.15-alpha...v3.9.17-alpha ## 3.9.15-alpha ## What's Changed * Add `versionHeightOffsetAppliesTo` property to version.json by @Copilot in dotnet/Nerdbank.GitVersioning#1279 ## New Contributors * @micheloliveira-com made their first contribution in dotnet/Nerdbank.GitVersioning#1277 **Full Changelog**: dotnet/Nerdbank.GitVersioning@v3.8.118...v3.9.15-alpha Commits viewable in [compare view](dotnet/Nerdbank.GitVersioning@v3.8.118...v3.9.50). </details> Updated [Nerdbank.GitVersioning](https://github.com/dotnet/Nerdbank.GitVersioning) from 3.8.118 to 3.9.50. <details> <summary>Release notes</summary> _Sourced from [Nerdbank.GitVersioning's releases](https://github.com/dotnet/Nerdbank.GitVersioning/releases)._ ## 3.9.50 ## What's Changed * Add `versionHeightOffsetAppliesTo` property to version.json by @Copilot in dotnet/Nerdbank.GitVersioning#1279 * Fix `nbgv prepare-release` command to honor inheriting version.json files by @AArnott in dotnet/Nerdbank.GitVersioning#1281 * Automatically disable git engine for Dependabot environments by @Copilot in dotnet/Nerdbank.GitVersioning#1284 * Add --what-if switch to nbgv tag command to preview tag names by @Copilot in dotnet/Nerdbank.GitVersioning#1287 * Auto-disable git engine for GitHub Copilot environments by @Copilot in dotnet/Nerdbank.GitVersioning#1291 * Allow uppercase letters in pre-release version identifiers by @Copilot in dotnet/Nerdbank.GitVersioning#1293 ## New Contributors * @micheloliveira-com made their first contribution in dotnet/Nerdbank.GitVersioning#1277 **Full Changelog**: dotnet/Nerdbank.GitVersioning@v3.8.118...v3.9.50 ## 3.9.37-alpha ## What's Changed * Auto-disable git engine for GitHub Copilot environments by @Copilot in dotnet/Nerdbank.GitVersioning#1291 **Full Changelog**: dotnet/Nerdbank.GitVersioning@v3.9.32-alpha...v3.9.37-alpha ## 3.9.32-alpha ## What's Changed * Automatically disable git engine for Dependabot environments by @Copilot in dotnet/Nerdbank.GitVersioning#1284 * Add --what-if switch to nbgv tag command to preview tag names by @Copilot in dotnet/Nerdbank.GitVersioning#1287 **Full Changelog**: dotnet/Nerdbank.GitVersioning@v3.9.17-alpha...v3.9.32-alpha ## 3.9.17-alpha ## What's Changed * Fix `nbgv prepare-release` command to honor inheriting version.json files by @AArnott in dotnet/Nerdbank.GitVersioning#1281 **Full Changelog**: dotnet/Nerdbank.GitVersioning@v3.9.15-alpha...v3.9.17-alpha ## 3.9.15-alpha ## What's Changed * Add `versionHeightOffsetAppliesTo` property to version.json by @Copilot in dotnet/Nerdbank.GitVersioning#1279 ## New Contributors * @micheloliveira-com made their first contribution in dotnet/Nerdbank.GitVersioning#1277 **Full Changelog**: dotnet/Nerdbank.GitVersioning@v3.8.118...v3.9.15-alpha Commits viewable in [compare view](dotnet/Nerdbank.GitVersioning@v3.8.118...v3.9.50). </details> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions </details> Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Updated [nbgv](https://github.com/dotnet/Nerdbank.GitVersioning) from 3.8.118 to 3.9.50. <details> <summary>Release notes</summary> _Sourced from [nbgv's releases](https://github.com/dotnet/Nerdbank.GitVersioning/releases)._ ## 3.9.50 ## What's Changed * Add `versionHeightOffsetAppliesTo` property to version.json by @Copilot in dotnet/Nerdbank.GitVersioning#1279 * Fix `nbgv prepare-release` command to honor inheriting version.json files by @AArnott in dotnet/Nerdbank.GitVersioning#1281 * Automatically disable git engine for Dependabot environments by @Copilot in dotnet/Nerdbank.GitVersioning#1284 * Add --what-if switch to nbgv tag command to preview tag names by @Copilot in dotnet/Nerdbank.GitVersioning#1287 * Auto-disable git engine for GitHub Copilot environments by @Copilot in dotnet/Nerdbank.GitVersioning#1291 * Allow uppercase letters in pre-release version identifiers by @Copilot in dotnet/Nerdbank.GitVersioning#1293 ## New Contributors * @micheloliveira-com made their first contribution in dotnet/Nerdbank.GitVersioning#1277 **Full Changelog**: dotnet/Nerdbank.GitVersioning@v3.8.118...v3.9.50 ## 3.9.37-alpha ## What's Changed * Auto-disable git engine for GitHub Copilot environments by @Copilot in dotnet/Nerdbank.GitVersioning#1291 **Full Changelog**: dotnet/Nerdbank.GitVersioning@v3.9.32-alpha...v3.9.37-alpha ## 3.9.32-alpha ## What's Changed * Automatically disable git engine for Dependabot environments by @Copilot in dotnet/Nerdbank.GitVersioning#1284 * Add --what-if switch to nbgv tag command to preview tag names by @Copilot in dotnet/Nerdbank.GitVersioning#1287 **Full Changelog**: dotnet/Nerdbank.GitVersioning@v3.9.17-alpha...v3.9.32-alpha ## 3.9.17-alpha ## What's Changed * Fix `nbgv prepare-release` command to honor inheriting version.json files by @AArnott in dotnet/Nerdbank.GitVersioning#1281 **Full Changelog**: dotnet/Nerdbank.GitVersioning@v3.9.15-alpha...v3.9.17-alpha ## 3.9.15-alpha ## What's Changed * Add `versionHeightOffsetAppliesTo` property to version.json by @Copilot in dotnet/Nerdbank.GitVersioning#1279 ## New Contributors * @micheloliveira-com made their first contribution in dotnet/Nerdbank.GitVersioning#1277 **Full Changelog**: dotnet/Nerdbank.GitVersioning@v3.8.118...v3.9.15-alpha Commits viewable in [compare view](dotnet/Nerdbank.GitVersioning@v3.8.118...v3.9.50). </details> Updated [Nerdbank.GitVersioning](https://github.com/dotnet/Nerdbank.GitVersioning) from 3.8.118 to 3.9.50. <details> <summary>Release notes</summary> _Sourced from [Nerdbank.GitVersioning's releases](https://github.com/dotnet/Nerdbank.GitVersioning/releases)._ ## 3.9.50 ## What's Changed * Add `versionHeightOffsetAppliesTo` property to version.json by @Copilot in dotnet/Nerdbank.GitVersioning#1279 * Fix `nbgv prepare-release` command to honor inheriting version.json files by @AArnott in dotnet/Nerdbank.GitVersioning#1281 * Automatically disable git engine for Dependabot environments by @Copilot in dotnet/Nerdbank.GitVersioning#1284 * Add --what-if switch to nbgv tag command to preview tag names by @Copilot in dotnet/Nerdbank.GitVersioning#1287 * Auto-disable git engine for GitHub Copilot environments by @Copilot in dotnet/Nerdbank.GitVersioning#1291 * Allow uppercase letters in pre-release version identifiers by @Copilot in dotnet/Nerdbank.GitVersioning#1293 ## New Contributors * @micheloliveira-com made their first contribution in dotnet/Nerdbank.GitVersioning#1277 **Full Changelog**: dotnet/Nerdbank.GitVersioning@v3.8.118...v3.9.50 ## 3.9.37-alpha ## What's Changed * Auto-disable git engine for GitHub Copilot environments by @Copilot in dotnet/Nerdbank.GitVersioning#1291 **Full Changelog**: dotnet/Nerdbank.GitVersioning@v3.9.32-alpha...v3.9.37-alpha ## 3.9.32-alpha ## What's Changed * Automatically disable git engine for Dependabot environments by @Copilot in dotnet/Nerdbank.GitVersioning#1284 * Add --what-if switch to nbgv tag command to preview tag names by @Copilot in dotnet/Nerdbank.GitVersioning#1287 **Full Changelog**: dotnet/Nerdbank.GitVersioning@v3.9.17-alpha...v3.9.32-alpha ## 3.9.17-alpha ## What's Changed * Fix `nbgv prepare-release` command to honor inheriting version.json files by @AArnott in dotnet/Nerdbank.GitVersioning#1281 **Full Changelog**: dotnet/Nerdbank.GitVersioning@v3.9.15-alpha...v3.9.17-alpha ## 3.9.15-alpha ## What's Changed * Add `versionHeightOffsetAppliesTo` property to version.json by @Copilot in dotnet/Nerdbank.GitVersioning#1279 ## New Contributors * @micheloliveira-com made their first contribution in dotnet/Nerdbank.GitVersioning#1277 **Full Changelog**: dotnet/Nerdbank.GitVersioning@v3.8.118...v3.9.15-alpha Commits viewable in [compare view](dotnet/Nerdbank.GitVersioning@v3.8.118...v3.9.50). </details> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions </details> Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Updated [nbgv](https://github.com/dotnet/Nerdbank.GitVersioning) from 3.8.118 to 3.9.50. <details> <summary>Release notes</summary> _Sourced from [nbgv's releases](https://github.com/dotnet/Nerdbank.GitVersioning/releases)._ ## 3.9.50 ## What's Changed * Add `versionHeightOffsetAppliesTo` property to version.json by @Copilot in dotnet/Nerdbank.GitVersioning#1279 * Fix `nbgv prepare-release` command to honor inheriting version.json files by @AArnott in dotnet/Nerdbank.GitVersioning#1281 * Automatically disable git engine for Dependabot environments by @Copilot in dotnet/Nerdbank.GitVersioning#1284 * Add --what-if switch to nbgv tag command to preview tag names by @Copilot in dotnet/Nerdbank.GitVersioning#1287 * Auto-disable git engine for GitHub Copilot environments by @Copilot in dotnet/Nerdbank.GitVersioning#1291 * Allow uppercase letters in pre-release version identifiers by @Copilot in dotnet/Nerdbank.GitVersioning#1293 ## New Contributors * @micheloliveira-com made their first contribution in dotnet/Nerdbank.GitVersioning#1277 **Full Changelog**: dotnet/Nerdbank.GitVersioning@v3.8.118...v3.9.50 ## 3.9.37-alpha ## What's Changed * Auto-disable git engine for GitHub Copilot environments by @Copilot in dotnet/Nerdbank.GitVersioning#1291 **Full Changelog**: dotnet/Nerdbank.GitVersioning@v3.9.32-alpha...v3.9.37-alpha ## 3.9.32-alpha ## What's Changed * Automatically disable git engine for Dependabot environments by @Copilot in dotnet/Nerdbank.GitVersioning#1284 * Add --what-if switch to nbgv tag command to preview tag names by @Copilot in dotnet/Nerdbank.GitVersioning#1287 **Full Changelog**: dotnet/Nerdbank.GitVersioning@v3.9.17-alpha...v3.9.32-alpha ## 3.9.17-alpha ## What's Changed * Fix `nbgv prepare-release` command to honor inheriting version.json files by @AArnott in dotnet/Nerdbank.GitVersioning#1281 **Full Changelog**: dotnet/Nerdbank.GitVersioning@v3.9.15-alpha...v3.9.17-alpha ## 3.9.15-alpha ## What's Changed * Add `versionHeightOffsetAppliesTo` property to version.json by @Copilot in dotnet/Nerdbank.GitVersioning#1279 ## New Contributors * @micheloliveira-com made their first contribution in dotnet/Nerdbank.GitVersioning#1277 **Full Changelog**: dotnet/Nerdbank.GitVersioning@v3.8.118...v3.9.15-alpha Commits viewable in [compare view](dotnet/Nerdbank.GitVersioning@v3.8.118...v3.9.50). </details> Updated [Nerdbank.GitVersioning](https://github.com/dotnet/Nerdbank.GitVersioning) from 3.8.118 to 3.9.50. <details> <summary>Release notes</summary> _Sourced from [Nerdbank.GitVersioning's releases](https://github.com/dotnet/Nerdbank.GitVersioning/releases)._ ## 3.9.50 ## What's Changed * Add `versionHeightOffsetAppliesTo` property to version.json by @Copilot in dotnet/Nerdbank.GitVersioning#1279 * Fix `nbgv prepare-release` command to honor inheriting version.json files by @AArnott in dotnet/Nerdbank.GitVersioning#1281 * Automatically disable git engine for Dependabot environments by @Copilot in dotnet/Nerdbank.GitVersioning#1284 * Add --what-if switch to nbgv tag command to preview tag names by @Copilot in dotnet/Nerdbank.GitVersioning#1287 * Auto-disable git engine for GitHub Copilot environments by @Copilot in dotnet/Nerdbank.GitVersioning#1291 * Allow uppercase letters in pre-release version identifiers by @Copilot in dotnet/Nerdbank.GitVersioning#1293 ## New Contributors * @micheloliveira-com made their first contribution in dotnet/Nerdbank.GitVersioning#1277 **Full Changelog**: dotnet/Nerdbank.GitVersioning@v3.8.118...v3.9.50 ## 3.9.37-alpha ## What's Changed * Auto-disable git engine for GitHub Copilot environments by @Copilot in dotnet/Nerdbank.GitVersioning#1291 **Full Changelog**: dotnet/Nerdbank.GitVersioning@v3.9.32-alpha...v3.9.37-alpha ## 3.9.32-alpha ## What's Changed * Automatically disable git engine for Dependabot environments by @Copilot in dotnet/Nerdbank.GitVersioning#1284 * Add --what-if switch to nbgv tag command to preview tag names by @Copilot in dotnet/Nerdbank.GitVersioning#1287 **Full Changelog**: dotnet/Nerdbank.GitVersioning@v3.9.17-alpha...v3.9.32-alpha ## 3.9.17-alpha ## What's Changed * Fix `nbgv prepare-release` command to honor inheriting version.json files by @AArnott in dotnet/Nerdbank.GitVersioning#1281 **Full Changelog**: dotnet/Nerdbank.GitVersioning@v3.9.15-alpha...v3.9.17-alpha ## 3.9.15-alpha ## What's Changed * Add `versionHeightOffsetAppliesTo` property to version.json by @Copilot in dotnet/Nerdbank.GitVersioning#1279 ## New Contributors * @micheloliveira-com made their first contribution in dotnet/Nerdbank.GitVersioning#1277 **Full Changelog**: dotnet/Nerdbank.GitVersioning@v3.8.118...v3.9.15-alpha Commits viewable in [compare view](dotnet/Nerdbank.GitVersioning@v3.8.118...v3.9.50). </details> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions </details> Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Updated [nbgv](https://github.com/dotnet/Nerdbank.GitVersioning) from 3.8.118 to 3.9.50. <details> <summary>Release notes</summary> _Sourced from [nbgv's releases](https://github.com/dotnet/Nerdbank.GitVersioning/releases)._ ## 3.9.50 ## What's Changed * Add `versionHeightOffsetAppliesTo` property to version.json by @Copilot in dotnet/Nerdbank.GitVersioning#1279 * Fix `nbgv prepare-release` command to honor inheriting version.json files by @AArnott in dotnet/Nerdbank.GitVersioning#1281 * Automatically disable git engine for Dependabot environments by @Copilot in dotnet/Nerdbank.GitVersioning#1284 * Add --what-if switch to nbgv tag command to preview tag names by @Copilot in dotnet/Nerdbank.GitVersioning#1287 * Auto-disable git engine for GitHub Copilot environments by @Copilot in dotnet/Nerdbank.GitVersioning#1291 * Allow uppercase letters in pre-release version identifiers by @Copilot in dotnet/Nerdbank.GitVersioning#1293 ## New Contributors * @micheloliveira-com made their first contribution in dotnet/Nerdbank.GitVersioning#1277 **Full Changelog**: dotnet/Nerdbank.GitVersioning@v3.8.118...v3.9.50 ## 3.9.37-alpha ## What's Changed * Auto-disable git engine for GitHub Copilot environments by @Copilot in dotnet/Nerdbank.GitVersioning#1291 **Full Changelog**: dotnet/Nerdbank.GitVersioning@v3.9.32-alpha...v3.9.37-alpha ## 3.9.32-alpha ## What's Changed * Automatically disable git engine for Dependabot environments by @Copilot in dotnet/Nerdbank.GitVersioning#1284 * Add --what-if switch to nbgv tag command to preview tag names by @Copilot in dotnet/Nerdbank.GitVersioning#1287 **Full Changelog**: dotnet/Nerdbank.GitVersioning@v3.9.17-alpha...v3.9.32-alpha ## 3.9.17-alpha ## What's Changed * Fix `nbgv prepare-release` command to honor inheriting version.json files by @AArnott in dotnet/Nerdbank.GitVersioning#1281 **Full Changelog**: dotnet/Nerdbank.GitVersioning@v3.9.15-alpha...v3.9.17-alpha ## 3.9.15-alpha ## What's Changed * Add `versionHeightOffsetAppliesTo` property to version.json by @Copilot in dotnet/Nerdbank.GitVersioning#1279 ## New Contributors * @micheloliveira-com made their first contribution in dotnet/Nerdbank.GitVersioning#1277 **Full Changelog**: dotnet/Nerdbank.GitVersioning@v3.8.118...v3.9.15-alpha Commits viewable in [compare view](dotnet/Nerdbank.GitVersioning@v3.8.118...v3.9.50). </details> Updated [Nerdbank.GitVersioning](https://github.com/dotnet/Nerdbank.GitVersioning) from 3.8.118 to 3.9.50. <details> <summary>Release notes</summary> _Sourced from [Nerdbank.GitVersioning's releases](https://github.com/dotnet/Nerdbank.GitVersioning/releases)._ ## 3.9.50 ## What's Changed * Add `versionHeightOffsetAppliesTo` property to version.json by @Copilot in dotnet/Nerdbank.GitVersioning#1279 * Fix `nbgv prepare-release` command to honor inheriting version.json files by @AArnott in dotnet/Nerdbank.GitVersioning#1281 * Automatically disable git engine for Dependabot environments by @Copilot in dotnet/Nerdbank.GitVersioning#1284 * Add --what-if switch to nbgv tag command to preview tag names by @Copilot in dotnet/Nerdbank.GitVersioning#1287 * Auto-disable git engine for GitHub Copilot environments by @Copilot in dotnet/Nerdbank.GitVersioning#1291 * Allow uppercase letters in pre-release version identifiers by @Copilot in dotnet/Nerdbank.GitVersioning#1293 ## New Contributors * @micheloliveira-com made their first contribution in dotnet/Nerdbank.GitVersioning#1277 **Full Changelog**: dotnet/Nerdbank.GitVersioning@v3.8.118...v3.9.50 ## 3.9.37-alpha ## What's Changed * Auto-disable git engine for GitHub Copilot environments by @Copilot in dotnet/Nerdbank.GitVersioning#1291 **Full Changelog**: dotnet/Nerdbank.GitVersioning@v3.9.32-alpha...v3.9.37-alpha ## 3.9.32-alpha ## What's Changed * Automatically disable git engine for Dependabot environments by @Copilot in dotnet/Nerdbank.GitVersioning#1284 * Add --what-if switch to nbgv tag command to preview tag names by @Copilot in dotnet/Nerdbank.GitVersioning#1287 **Full Changelog**: dotnet/Nerdbank.GitVersioning@v3.9.17-alpha...v3.9.32-alpha ## 3.9.17-alpha ## What's Changed * Fix `nbgv prepare-release` command to honor inheriting version.json files by @AArnott in dotnet/Nerdbank.GitVersioning#1281 **Full Changelog**: dotnet/Nerdbank.GitVersioning@v3.9.15-alpha...v3.9.17-alpha ## 3.9.15-alpha ## What's Changed * Add `versionHeightOffsetAppliesTo` property to version.json by @Copilot in dotnet/Nerdbank.GitVersioning#1279 ## New Contributors * @micheloliveira-com made their first contribution in dotnet/Nerdbank.GitVersioning#1277 **Full Changelog**: dotnet/Nerdbank.GitVersioning@v3.8.118...v3.9.15-alpha Commits viewable in [compare view](dotnet/Nerdbank.GitVersioning@v3.8.118...v3.9.50). </details> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions </details> Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Motivation
As described in the official announcement, the new Trusted Publishing feature greatly enhances package publishing security on NuGet.org.
We successfully tested this approach with our own NuGet library:
Required changes in this repository
secrets.NUGET_USERto this repository, using the NuGet.org username (profile name) of the package owner (Nerdbank in this case).secrets.NUGET_API_KEYsecret can be removed from this repository and also from the NuGet.org account if it was only used here.One-time configuration on NuGet.org
According to the documentation:
Nerdbank).dotnet).Nerdbank.GitVersioning)..github/workflows/(e.g.release.yml).This setup eliminates the need for long-lived API keys and improves the overall security of the publishing process.