dev/release: explore trusted publishing mechanisms
Open
Type: enhancement
- Dominant language
- C#
- Stars
- 627
- Forks
- 217
- Avg merge
- 17h
- Merged PRs (30d)
- 57
Description
### What feature or improvement would you like to see?
Currently we have maintainers deploy release artifacts with API keys, but package indices are encouraging workflows that are more secure and don't depend on this.
Contributor guide
Research direction
Start by documenting how maintainers currently deploy release artifacts with API keys and which package indices are involved. Compare the trusted-publishing mechanisms those indices encourage, then define a concrete replacement and verification criteria for secure releases.
Written by the indexing model from the issue text.
Assessment
- Domain
- release, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100