Skip to content

Authorize PyPI with OICD #51

@eggplants

Description

@eggplants

For GitHub Actions that publish packages, configure OAuth on the PyPI side to authorize each request individually. This allows to remove the API token from repo secrets.

Docs:
https://docs.pypi.org/trusted-publishers/
https://docs.pypi.org/trusted-publishers/adding-a-publisher/
My example:
https://github.com/eggplants/getjump/blob/master/.github/workflows/release.yml#L23-L36

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions