Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →You can publish a Chrome extension from GitHub Actions without keeping a long-lived Google credential in repository secrets. Use GitHub Actions OpenID Connect (OIDC) with Google Cloud Workload Identity Federation to authenticate the workflow at runtime, let its federated identity impersonate a Google Cloud service account, and authorize that service account in your Chrome Web Store publisher account. The workflow then uses Chrome Web Store API v2 to upload the updated package and submit it for review.
This removes persisted Google key material from GitHub secrets; it does not eliminate credentials altogether. The workflow receives short-lived credentials when it runs, and Google Cloud IAM and Chrome Web Store permissions still need careful configuration.
How the keyless publishing setup works
The authentication path has three parts: GitHub identifies the workflow run with an OIDC token; Google Cloud Workload Identity Federation checks that token against your configured trust rules; and the accepted identity impersonates a service account that the Chrome Web Store publisher account recognizes. The workflow exchanges the OIDC token for short-lived Google credentials and uses them to call the store API.
Google Cloud describes Workload Identity Federation as eliminating the maintenance and security burden associated with service-account keys. GitHub likewise documents using OIDC to access Google Cloud without storing long-lived credentials as GitHub secrets. See Google Cloud Workload Identity Federation and GitHub’s OIDC configuration guide for Google Cloud.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
- Read Before You Buy — No Video Output: These adapters support charging and USB 2.0 data transfer, but cannot transmit video signals. Except for standard USB webcams (which use USB data only), they are not compatible with HDMI/DisplayPort cables, video-capable USB-C hubs, or docking stations with video output.
- Convert USB-A Ports to USB-C: Designed to connect USB-C earphones, cables, flash drives, card readers, and other USB-C accessories to standard USB-A ports. Plug-and-play with no drivers or software required.
- Aluminum Alloy Housing: Built with a sturdy aluminum alloy shell that aids in heat dissipation and protects against daily wear and scratches. Designed to maintain a stable and secure connection.
- Compact & Travel-Friendly: The ultra-compact design allows the adapter to stay plugged into your device without blocking adjacent ports or adding bulk, reducing wear and tear on your original USB ports.
- 12-Month Warranty: Backed by a 12-month manufacturer warranty for peace of mind. Designed to meet strict quality control standards for reliable everyday performance.
What you need before configuring the workflow
- A Chrome Web Store publisher account and the extension already created as an item if you are automating an update.
- A Google Cloud project where an administrator can enable the Chrome Web Store API, create a service account, and configure Workload Identity Federation and IAM.
- A GitHub repository and release workflow whose identity can be restricted precisely in Google Cloud trust conditions.
- Access to the Chrome Web Store Developer Dashboard publisher account to authorize the service-account email.
- For publishing or updating an existing extension, 2-step verification on the developer account. For a new item, the Store Listing and Privacy tabs must be completed before publishing, according to the Chrome Web Store API usage guide.
Configure Google Cloud and Chrome Web Store access
1. Enable the API and create a service account
In the intended Google Cloud project, enable the Chrome Web Store API and create a service account for the publishing workflow. Add that account’s email to the Chrome Web Store Developer Dashboard under Account. The official service-account instructions say a publisher can add only one service account, so check the publisher account’s existing configuration before proceeding.
2. Create a narrowly scoped GitHub identity provider
Create a Workload Identity Federation pool and provider for GitHub’s OIDC issuer. Map the claims you need and set attribute conditions so only the intended repository and workflow identity can federate. Grant that federated principal permission to impersonate the publishing service account.
Rank #2
- 5-in-1 USB-C Hub: Experience comprehensive connectivity featuring a Power Delivery input, two USB-A 2.0 ports, a USB-A 3.0 port, and an HDMI port. (Note: The USB-C power delivery input port is only for connecting an external wall charger to power your laptop and cannot power peripheral devices.)
- 90W Pass-Through Charging: Achieve optimal charging with 90W pass-through power to your laptop, supported by a total input of 100W, with the hub reserving 10W for operational efficiency. (Note: Wall charger not included.)
- Quick Data Transfers: Accelerate your productivity with rapid data transfers using a high-speed 5Gbps USB 3.0 port and two 480Mbps USB 2.0 ports.
- 4K HDMI Display: Enhance your visual experience with a hub capable of delivering 4K resolution at 30Hz in both mirror and extend modes. Please note that this hub is compatible with MacBook (macOS 12 and newer), Windows 10 and 11, ChromeOS, and laptops equipped with DP Alt Mode and Power Delivery. Note: This device is not compatible with Linux.
- What You Get: Anker USB-C Hub (5-in-1, 4K HDMI), welcome guide, 18-month warranty, and our friendly customer service.
Do not trust every repository or workflow in an organization by default. GitHub warns that OIDC trust should be restricted so untrusted repositories cannot obtain credentials. If the deployment uses a GitHub environment, configure environment protection rules as an additional gate. The details of claim mapping and IAM bindings depend on your Google Cloud project and trust design; follow the current GitHub configuration guide and Google Cloud federation documentation.
Give the release job OIDC access
The GitHub Actions job that performs deployment must request an OIDC token. Grant id-token: write at the job level where possible, rather than across unrelated jobs, and use Google’s google-github-actions/auth action or an equivalent supported exchange flow to obtain short-lived credentials through Workload Identity Federation. Configure the action for the workload identity provider and service account you created; do not add a service-account JSON private key or OAuth refresh token as a substitute if the goal is to avoid stored long-lived credentials.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Rank #3
- Sleek 7-in-1 USB-C Hub: Features an HDMI port, two USB-A 3.0 ports, and a USB-C data port, each providing 5Gbps transfer speeds. It also includes a USB-C PD input port for charging up to 100W and dual SD and TF card slots, all in a compact design.
- Flawless 4K@60Hz Video with HDMI: Delivers exceptional clarity and smoothness with its 4K@60Hz HDMI port, making it ideal for high-definition presentations and entertainment. (Note: Only the HDMI port supports video projection; the USB-C port is for data transfer only.)
- Double Up on Efficiency: The two USB-A 3.0 ports and a USB-C port support a fast 5Gbps data rate, significantly boosting your transfer speeds and improving productivity.
- Fast and Reliable 85W Charging: Offers high-capacity, speedy charging for laptops up to 85W, so you spend less time tethered to an outlet and more time being productive.
- What You Get: Anker USB-C Hub (7-in-1), welcome guide, 18-month warranty, and our friendly customer service.
Keep the release workflow protected by your repository’s normal deployment controls. A workflow permission alone is not a safe trust policy: Google Cloud’s provider conditions must also constrain which GitHub identity can impersonate the service account.
Upload the extension package, then submit it
1. Increment the extension version
For an update to an existing store item, increment the version in the extension’s manifest and build the package you intend to release. The Chrome Web Store API usage guide says an upload fails if the version was not increased.
Rank #4
- Dual Converters, Infinite Potential:Includes 2× USB C male to USB A female adapters and 2× USB A male to USB C female adapters. Perfect for a wide range of uses—tablets with Bluetooth keyboards, expand USB ports on macbook, and more. Two different converters for all your daily needs
- Next-Level 10Gbps & 3A Charging: No more slow 480Mbps, this usb to usb c adapter has a transfer speed of up to 10Gbps, allowing you to do more transferring in less time. This usb adapter fits both USB A and USB C charger, supporting up to 3A fast charging
- Upgraded Exquisite Craftsmanship: With an aluminum alloy housing and metal connector, the usbc to usb adapter is extremely durable and sturdy. Rigorously tested to withstand more than 10,000 times of plugging and unplugging, ensuring long-lasting performance
- Broad Compatible: The usb c to usb adapter widely supports all USB C/ USB A devices like laptops, tablets, cellphones, car chargers, and phone chargers. Such as compatible with MacBook Pro/Air 2023/2022, Thunderbolt 4/3 Devices,Apple MagSafe Watch 9/8/7/SE/Ultra, iPad Pro 2022/2021, Samsung Galaxy S23/S20/S10, and iPhone 17/16/15 Pro. Plug and play
- Please Note: To reach 10Gbps speed, keep the cable under 3.3 ft. For USB A Male to USB C adapters, try flipping the USB C connector. USB C Male to USB A adapters support bidirectional 10Gbps transfer within 3.3 ft
2. Upload the package with API v2
Use the v2 media upload method for the existing item. Its resource name includes the publisher ID and extension item ID; these must correspond to the publisher account and extension you intend to update. See the official v2 media.upload reference.
3. Submit the uploaded item for publication
After a successful upload, call the v2 publish method for that item. The normal path submits the update for review, and publication follows approval; an API upload or publish call does not guarantee immediate public availability. The publish method reference documents STAGED_PUBLISH for an approved submission that should remain staged until a later developer action.
Recommended Free Tools
Best Value
- 5-in-1 Connectivity: Equipped with a 4K HDMI port, a 5 Gbps USB-C data port, two 5 Gbps USB-A ports, and a USB C 100W PD-IN port. Note: The USB C 100W PD-IN port supports only charging and does not support data transfer devices such as headphones or speakers.
- Powerful Pass-Through Charging: Supports up to 85W pass-through charging so you can power up your laptop while you use the hub. Note: Pass-through charging requires a charger (not included). Note: To achieve full power for iPad, we recommend using a 45W wall charger.
- Transfer Files in Seconds: Move files to and from your laptop at speeds of up to 5 Gbps via the USB-C and USB-A data ports. Note: The USB C 5Gbps Data port does not support video output.
- HD Display: Connect to the HDMI port to stream or mirror content to an external monitor in resolutions of up to 4K@30Hz. Note: The USB-C ports do not support video output.
- What You Get: Anker 332 USB-C Hub (5-in-1), welcome guide, our worry-free 18-month warranty, and friendly customer service.
The skipReview option is an attempt to skip review, not a promise. The API can return a validation error when review is required, so build your release process around the ordinary review path rather than treating review bypass as assured.
Choose federation over a stored credential
| Approach | Credential behavior | What it requires | Fit for this goal |
|---|---|---|---|
| OIDC federation with service-account impersonation | No long-lived Google service-account key needs to be stored in GitHub; the workflow obtains short-lived credentials at runtime. | Workload Identity Federation pool and provider, restrictive trust conditions, service-account impersonation permission, and Chrome publisher authorization. | Recommended when administrators can configure Google Cloud IAM. |
| Service-account JSON key | A persistent private key is stored and must be protected and rotated. | Key creation, secure secret handling, rotation, and Chrome publisher authorization. | Possible, but does not meet the aim of avoiding a stored long-lived Google credential. |
| OAuth client and refresh token | Durable OAuth credential material must be maintained. | OAuth client setup and refresh-token management. | Documented in the older API usage tutorial, but not the best fit for a no-stored-secret workflow. |
The Chrome Web Store API v2 reference supports service accounts. Its documentation also notes that the API is primarily intended for managing your own extension, and that a “verified” status may not be available for apps using the Chrome Web Store write API scope; the documentation says that this unverified status does not prevent API use. See the Chrome Web Store API reference.
Use API v2 and account for the v1 transition
Use Chrome Web Store API v2 for new automation. As of October 5, 2026, the archived v1 reference listed October 15, 2026 as its support end date, a near-term deadline; recheck the current status before implementing or maintaining an integration after that date. The v1 page is available at Chrome Web Store API (V1) Reference.
Quick Recap
Release-readiness checks
- Verify the Google Cloud project and Chrome Web Store publisher account are the intended production accounts.
- Confirm the service account is the one authorized in the publisher account, and account for the documented one-service-account publisher limit.
- Review provider attribute conditions against the exact repository and release workflow identity; add environment protections when using GitHub environments.
- Scope
id-token: writeto the deployment job where practical. - Confirm the extension manifest version was incremented and the upload targets the right publisher and item IDs.
- Expect review before publication unless the API accepts a review-skip request for that item; do not promise a release time based on the API call alone.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

