Context & Problem
Currently, pub.dev only exposes PUT /api/packages/<package>/publishing (gated behind web session cookies). There is no programmatic GET endpoint to retrieve a package's publishing configuration.
This prevents:
- GitHub Actions & CI Pipelines: Automated workflows cannot verify whether their repository, environment, and tag patterns match the registered package configuration before attempting release or publish steps.
- Developer & Agent Tooling: CLI tools and AI coding assistants cannot inspect automated publishing settings, manual publishing locks, or GCP service account associations using stored credentials.
Proposed Solution
Add an authenticated GET /api/packages/<package>/publishing endpoint in pubapi.dart returning the PkgPublishingConfig payload.
Authorization Matrix
The endpoint requires a valid Bearer token (requireAuthenticatedClient()):
| Caller Identity |
Condition for Access |
Unauthorized Error |
| User (OAuth) |
Caller is a package admin or publisher admin |
403 Forbidden (InsufficientPermissions) |
| GitHub Action (OIDC) |
agent.payload.repository == githubConfig.repository |
403 Forbidden (InsufficientPermissions) |
| GCP Service Account (OIDC) |
agent.email == gcpConfig.serviceAccountEmail |
403 Forbidden (InsufficientPermissions) |
| Anonymous / Expired |
Missing or invalid Bearer token |
401 Unauthorized (MissingAuthentication) |
Note: For GitHub Actions OIDC introspection, only the repository identity is validated; tag pattern and environment constraints are only enforced during pub publish.
Acceptance Criteria
Related Issues
Context & Problem
Currently,
pub.devonly exposesPUT /api/packages/<package>/publishing(gated behind web session cookies). There is no programmaticGETendpoint to retrieve a package's publishing configuration.This prevents:
Proposed Solution
Add an authenticated
GET /api/packages/<package>/publishingendpoint inpubapi.dartreturning thePkgPublishingConfigpayload.Authorization Matrix
The endpoint requires a valid Bearer token (
requireAuthenticatedClient()):403 Forbidden(InsufficientPermissions)agent.payload.repository == githubConfig.repository403 Forbidden(InsufficientPermissions)agent.email == gcpConfig.serviceAccountEmail403 Forbidden(InsufficientPermissions)401 Unauthorized(MissingAuthentication)Note: For GitHub Actions OIDC introspection, only the repository identity is validated; tag pattern and environment constraints are only enforced during
pub publish.Acceptance Criteria
GET /api/packages/<package>/publishingroute inpubapi.dartandpubapi.client.dart.packageBackend.getPackagePublishing(String package)with authorization checks for User admins, GitHub Actions OIDC tokens, and GCP Service Accounts.PkgPublishingConfig(GitHub config, GCP config, and manual publishing restriction status).Related Issues
isManualPublishingDisabled)