diff --git a/.github/workflows/packages.yml b/.github/workflows/packages.yml index ebc1c909..4763f3a8 100644 --- a/.github/workflows/packages.yml +++ b/.github/workflows/packages.yml @@ -112,12 +112,14 @@ jobs: API_KEY: ${{ secrets.FEEDZ_API_KEY }} run: | if [ -z "$API_KEY" ]; then - echo "::error::API key for feedz.io is empty. Check the secret or the NuGet login (OIDC) step output that feeds it; nothing was pushed." + echo "::error::API key for feedz.io is empty. Check the FEEDZ_API_KEY repository secret; nothing was pushed." exit 1 fi - name: Publish to feedz.io - run: dotnet nuget push *.nupkg -k ${{ secrets.FEEDZ_API_KEY }} -s ${{ env.feedz_feed_source }} --skip-duplicate + env: + API_KEY: ${{ secrets.FEEDZ_API_KEY }} + run: dotnet nuget push *.nupkg -k "$API_KEY" -s ${{ env.feedz_feed_source }} --skip-duplicate publish_nuget: name: Publish release to nuget.org @@ -150,9 +152,11 @@ jobs: API_KEY: ${{ steps.nuget_login.outputs.NUGET_API_KEY }} run: | if [ -z "$API_KEY" ]; then - echo "::error::API key for nuget.org is empty. Check the secret or the NuGet login (OIDC) step output that feeds it; nothing was pushed." + echo "::error::API key for nuget.org is empty. Check the NuGet login (OIDC) step output and the Trusted Publishing policy on nuget.org; nothing was pushed." exit 1 fi - name: Publish to nuget.org - run: dotnet nuget push *.nupkg -k ${{ steps.nuget_login.outputs.NUGET_API_KEY }} -s ${{ env.nuget_feed_source }} --skip-duplicate + env: + API_KEY: ${{ steps.nuget_login.outputs.NUGET_API_KEY }} + run: dotnet nuget push *.nupkg -k "$API_KEY" -s ${{ env.nuget_feed_source }} --skip-duplicate