Repository navigation
Fetch organization packages with Workload Identity - #1266
Merged
Merged
Conversation
In a GitHub Actions job with the id-token: write permission, fetching packages from an organization's repository exchanges the job's OIDC token for a short-lived repository token when no organization key or authenticated user is configured. hex_core's repository auth resolution does the exchange. Hex keeps the outcome, a token or why there is none, in memory through the new callbacks, so it's never written to the Hex config and a failed exchange isn't repeated for every package. Before the registry prefetch, the converger exchanges once per organization instead of asking to authenticate a user, and says when the job authenticated with a workload identity. After a failed exchange a fetch runs without credentials, so .netrc credentials for a mirror still apply, and a fetch the repository refuses reports why the exchange failed instead of printing a term or asking to run mix hex.user auth. Updates the vendored hex_core to 6ded3af.
Those versions reject a pinned variable on the left of <> in a match, so the expected message is built before the assertion.
Name who exchanges the OIDC token instead of using the passive voice in the mix hex.publish and mix hex.organization docs and the changelog entry. The facts are unchanged.
ericmj
marked this pull request as ready for review
October 10, 2026 12:10
ericmj
added a commit
to hexpm/hexpm
that referenced
this pull request
Oct 10, 2026
…d the Workload Identity docs (#2022) * Reword the Workload Identity docs Split sentences joined by semicolons, name who does what instead of using the passive voice, use contractions, drop the bold lead-ins from the empty-field list and replace phrasing like "publish-oriented", "land the first release" and "put a gate in front of a publish" with what it means. The facts are unchanged. * Document that Mix fetches with organization workload identities When Mix fetches packages from an organization's repository in a GitHub Actions job with the id-token: write permission, and neither an organization key nor an authenticated user is configured, it exchanges the job's OIDC token for a repository token (hexpm/hex#1266). Say so in the organization section and remove the limitation saying it doesn't.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
In a GitHub Actions job with the
id-token: writepermission, fetching packages from an organization's repository now exchanges the job's OIDC token for a short-lived repository token when no organization key or authenticated user is configured. The exchange is in hex_core, hexpm/hex_core#238, vendored here at 6ded3af. The vendored copy needs updating once that's merged, since the squash changes the commit.Hex.Statethrough the new hex_core callbacks, never in the Hex config..netrccredentials for a mirror still apply. A registry, policy or tarball fetch the repository refuses prints why the exchange failed and suggestsmix hex.organization auth ORG --key KEY.mix hex.organizationdocs now cover fetching.hexpm's Workload Identity docs say Mix and rebar3 don't request repository tokens (https://github.com/hexpm/hexpm/blob/a746876ae838334007a3f0a956745fe5bcaa8768/lib/hexpm_web/templates/docs/workload_identity.html.md?plain=1#L222), which needs updating when this is released.