Document reusable workflow support for trusted publishing #410
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Summary
Context
This documentation accompanies the feature implementation in rubygems/rubygems.org#6184, which adds support for GitHub Actions reusable workflows in trusted publishing.
When a repository uses a reusable workflow from a different repository (e.g., a shared release workflow), the OIDC token's
job_workflow_refclaim points to the shared workflow's location rather than the calling repository. The new fields allow users to specify where the workflow file actually lives.