Publishing happens in CI through RubyGems Trusted Publishing (OIDC). No API key is
stored anywhere — deploy.yml exchanges the GitHub OIDC token for a push-scoped
RubyGems key that expires in 15 minutes.
-
Bump
VERSIONinlib/segment/analytics/version.rb. -
In
History.md, change theUnreleasedheading toX.Y.Z / YYYY-MM-DD. -
git commit -am "Release X.Y.Z." -
Open a PR and merge it to
master. -
Tag the merged commit — no
vprefix:git tag X.Y.Z && git push origin X.Y.Z -
Create a GitHub Release for that tag.
deploy.ymltriggers onrelease: published; pushing the tag by itself does not start it. -
Approve the
productionenvironment when the publish job requests review.
The workflow verifies the tag against version.rb, builds the gem, and pushes it.
Note: the trusted publisher on rubygems.org is registered against repository
segmentio/analytics-ruby, workflowdeploy.ymland environmentproduction. All three must match the workflow or the OIDC exchange fails.