Skip to content

fix(ci): use rubygems/release-gem@v1 for OIDC trusted publishing#2

Merged
doris-xiao-bybit merged 1 commit into
mainfrom
fix/publish-workflow-oidc
Jul 22, 2026
Merged

fix(ci): use rubygems/release-gem@v1 for OIDC trusted publishing#2
doris-xiao-bybit merged 1 commit into
mainfrom
fix/publish-workflow-oidc

Conversation

@doris-xiao-bybit

Copy link
Copy Markdown
Collaborator

The previous publish step invoked gem exec rubygems-trusted-publishing, which references a gem that doesn't exist on rubygems.org — failing every release with:

Could not find a valid gem 'rubygems-trusted-publishing' (>= 0)

The rubygems/release-gem@v1 action is the officially-supported way to do OIDC-based trusted publishing: it requests a token from GitHub's OIDC provider (using id-token: write), exchanges it for a short-lived rubygems.org API key, and runs gem build + gem push with that key.

Requirements on the rubygems.org side (already configured for bybit-exchange/bybit.ruby.api):

  • Trusted publisher for the correct repo + workflow filename
  • Environment field on rubygems must match the workflow's environment (or both must be empty — our workflow has no environment)

Also drops the RUBYGEMS_API_KEY fallback: trusted publishing is the only supported path going forward, and mixing OIDC with an API-key secret would introduce a confusing race.

The previous publish step invoked `gem exec rubygems-trusted-publishing`,
which references a gem that doesn't exist on rubygems.org — failing every
release with:

    Could not find a valid gem 'rubygems-trusted-publishing' (>= 0)

The rubygems/release-gem@v1 action is the officially-supported way to do
OIDC-based trusted publishing: it requests a token from GitHub's OIDC
provider (using `id-token: write`), exchanges it for a short-lived
rubygems.org API key, and runs `gem build` + `gem push` with that key.

Requirements on the rubygems.org side (already configured for
bybit-exchange/bybit.ruby.api):
- Trusted publisher for the correct repo + workflow filename
- Environment field on rubygems must match the workflow's environment (or
  both must be empty — our workflow has no environment)

Also drops the RUBYGEMS_API_KEY fallback: trusted publishing is the only
supported path going forward, and mixing OIDC with an API-key secret would
introduce a confusing race.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@doris-xiao-bybit
doris-xiao-bybit merged commit f1414c7 into main Jul 22, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant