Skip to content

ci(rust-release): publish to crates.io via Trusted Publishing - #2433

Merged
ArthurZucker merged 1 commit into
mainfrom
ci/crates-io-trusted-publishing
Sep 21, 2026
Merged

ArthurZucker merged 1 commit into
mainfrom
ci/crates-io-trusted-publishing

Conversation

@ArthurZucker

Copy link
Copy Markdown
Collaborator

Drops the long-lived secrets.CRATES_TOKEN from the Rust release. The job now mints an OIDC id-token and rust-lang/crates-io-auth-action exchanges it for a registry token that crates.io revokes when the run ends.

python-release.yml already does the equivalent for PyPI (#2425), so this brings the Rust half in line.

What changed

  • permissions: id-token: write on rust_publish
  • a crates-io environment, so required reviewers can gate a publish
  • rust-lang/crates-io-auth-action@c6f97d4 (v1.0.5), SHA-pinned like the rest of our actions
  • both publish steps read steps.auth.outputs.token instead of secrets.CRATES_TOKEN

The auth step is gated on refs/tags/v*: cargo publish --dry-run never authenticates, so workflow_dispatch runs keep working with no Trusted Publishing config at all. That means this PR is safe to merge before the crates.io side is configured — only a real tag needs it.

Before the next tag: crates.io config is required, per crate

Trusted Publishing is configured on each crate at crates.io/crates/<crate>/settings/trusted-publishing, with:

Field Value
Repository owner huggingface
Repository name tokenizers
Workflow filename rust-release.yml
Environment crates-io (or blank to accept any)

Only tokenizers can be configured today. The other five crates this workflow publishes — bitcanon, tk-encode, tk-convert, tk-serialize, tk-train — do not exist on crates.io yet, and crates.io has no pending-publisher state (RFC 3691 lists it as a future enhancement). Each needs one token-based publish before a Trusted Publisher can be attached to it.

So the first release of the new crates still needs a token; every release after that does not.

Replaces the long-lived `secrets.CRATES_TOKEN` with an OIDC exchange: the job
mints an id-token, `rust-lang/crates-io-auth-action` trades it for a registry
token that crates.io revokes when the run ends. Nothing long-lived is stored.

Tags only. `cargo publish --dry-run` never authenticates, so `workflow_dispatch`
runs keep working without any Trusted Publishing config.

The `crates-io` environment is there to hang required reviewers off the publish,
and must match the Environment field on each crate's crates.io entry (blank
there accepts any).
@HuggingFaceDocBuilderDev

Copy link
Copy Markdown

The docs for this PR live here. All of your documentation changes will be reflected on that endpoint. The docs are available until 30 days after the last update.

@ArthurZucker
ArthurZucker merged commit 47e3f23 into main Sep 21, 2026
25 checks passed
@ArthurZucker
ArthurZucker deleted the ci/crates-io-trusted-publishing branch September 21, 2026 04:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants