Skip to main content

Module oidc

Module oidc 

Source
Expand description

Publishing from GitHub Actions without a secret (RFC-108 D5).

A job asks the runner for an OIDC token whose audience is the console’s URL and sends it as Authorization: Bearer. Verifier::verify checks the token’s signature against the issuer’s published keys, its issuer, audience, and validity window, and that the repository’s owner is one the console trusts. The caller then binds the report to the token’s repository claim.

Structs§

Trust
A source of tokens the console accepts: github:<owner>. The provider prefix is kept so GitHub Enterprise Server and GitLab can be added without changing how trusts are stored or shown.
VerifiedToken
The claims of an accepted token the console uses.
Verifier
Verifies GitHub Actions tokens for one console.

Enums§

OidcError
Why a token was not accepted.

Constants§

GITHUB_ISSUER
iss of a GitHub Actions token.
GITHUB_JWKS_URL
Where GitHub publishes the keys that sign its tokens.