
Nuget Trusted Publishing
by dotnet0608d8924cd3MIT5.5K starsListed Oct 8, 2026Updated Oct 8, 2026Repository updated today
Set up NuGet trusted publishing (OIDC) on a GitHub Actions repo — replaces long-lived API keys with short-lived tokens. USE FOR: trusted publishing, NuGet OIDC, keyless NuGet publish, migrate from NuGet API key, NuGet/login, secure NuGet publishing. DO NOT USE FOR: publishing to private feeds or Azure Artifacts (OIDC is nuget.org only). INVOKES: shell (powershell or bash), edit, create, ask_user for guided repo setup.
Add to a SourceWeft workspace
- Open the skill in your dashboard and add it to a workspace.
- Enable it for the chats that should use it.
This skill is instructions only: it ships no scripts to execute.
Add to SourceWeftYou will be asked to sign in first, then taken straight to this skill.
Ask your agent to install it
Paste this prompt into Claude Code, Codex, Cursor or another agent that can run commands — or into SourceWeft chat. The agent reads this skill's install guide, shows you its source, license and scripts, and installs it with the SourceWeft CLI once you agree.
Read https://sourceweft.com/skills/gh-dotnet-skills-nuget-trusted-publishing/install.md and install the skill it describes. Before installing, show me its source, license and whether it ships scripts, and wait for my OK. Ask me before changing anything else on my machine.Install it yourself from a terminal
For Claude Code, Codex, Cursor and other local agents. The SourceWeft CLI fetches the skill from its source repository at the commit scanned here, and verifies every file against the hashes recorded when the skill was scanned. If anything differs, nothing is written.
npx @sourceweft/cli skills install gh-dotnet-skills-nuget-trusted-publishingAdd --agent claude-code, codex, cursor or universal to choose which agent gets it (Claude Code by default).
Upstream installer — not verified by SourceWeft
The open-source skills installer fetches the same pinned commit, but does not check the files against the hashes SourceWeft recorded.
npx skills add https://github.com/dotnet/skills/tree/0608d8924cd3173411e36650a7a01b4063e1f55a/plugins/dotnet-advanced/skills/nuget-trusted-publishingSource and attribution
Source:dotnet/skillsinplugins/dotnet-advanced/skills/nuget-trusted-publishingat commit0608d89
License: MIT
Content belongs to its original authors. SourceWeft indexes it from a public repository.
More from dotnet/skills

Setup Local Sdk
dotnet
Guides installing a project-local .NET SDK in .dotnet/ and wiring it through global.json paths.

System Text Json Net11
dotnet
Guides use of three System.Text.Json APIs added in .NET 11: PascalCase naming policy and generic type-info accessors.

Thread Abort Migration
dotnet
Guides migrating .NET Framework Thread.Abort usage to cooperative cancellation in modern .NET.

Migrate Dotnet9 To Dotnet10
dotnet
Guides migration of a .NET 9 project or solution to .NET 10, resolving breaking changes.

Target Authoring
dotnet
Canonical patterns for authoring custom MSBuild targets, including dependency chains, extension, and incrementality.

Resolve Project References
dotnet
Explains why ResolveProjectReferences time in MSBuild summaries is misleading and redirects optimization to task self-time.
More in DevOps & Cloud

Playwright Devops
microsoft
DevOps workflows for Playwright: analyze GitHub Actions failures for the last commit on main and fetch failed job logs.

M5 Onboard
anthropics
Provisions M5Stack ESP32 boards by detecting them on USB, flashing UIFlow 2.0 firmware, and installing a MicroPython app bundle.
Yeet
openai
Stages, commits, pushes, and opens or updates a GitHub pull request in one flow using the GitHub CLI.

Runbook
anthropics
Creates or updates step-by-step operational runbooks for recurring tasks, including troubleshooting, rollback and escalation.

Incident Response
anthropics
Guides an incident response workflow: severity triage, status updates, mitigation tracking, and blameless postmortems.

Deploy Checklist
anthropics
Generates a pre-deployment readiness checklist covering pre-deploy, deploy, post-deploy and rollback triggers.