Developer details automated VS Code extension publishing without persistent tokens
A developer has documented a method for publishing VS Code extensions without storing a long-lived personal access token. The process involves separating packaging, authentication, federation, publisher access, and Marketplace verification into distinct steps. Authentication is handled using GitHub Actions OIDC tokens exchanged through Microsoft Entra ID, avoiding client secrets in the repository. The developer encountered and resolved issues with workflow subjects and publisher permissions during the release of version 0.0.2. The key lesson emphasizes that a successful build does not guarantee authentication or publishing rights.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in