Proposal: use GitHub OIDC for Chrome Web Store publishing #1041
|
Hi Voyager maintainers, I noticed Would it be useful to migrate the Chrome upload paths to GitHub OIDC and Google Workload Identity Federation, so the workflows use short-lived access tokens instead of a stored refresh token? The normal release currently creates a store-only I maintain Publish to Chrome Web Store, a GitHub Action for Chrome Web Store API v2 publishing with a short-lived token. I would propose it for an isolated Chrome publish job, but can adapt to another publisher if you prefer. If this sounds useful, a possible scope is:
One detail to settle is that the manual retry runs from I have not changed code. The contribution guide asks for maintainer approval before implementing a new workflow feature, so I will wait for your direction before preparing a PR. |
Replies: 2 comments
|
Thanks for the proposal! We're fine with the current setup for now and would prefer not to add a third-party publish action. Will revisit if we decide to move to OIDC. |
|
Sure NP. I’ll leave the WIF setup documentation here in case you revisit OIDC in the future. Happy to help if you do. |
Thanks for the proposal! We're fine with the current setup for now and would prefer not to add a third-party publish action. Will revisit if we decide to move to OIDC.