Skip to content

Switch to trusted publishing #263

@Cito

Description

@Cito

We should switch to Trusted Publishing for our releases. Trusted publishing replaces a persistent secret that can leak with a cryptographically scoped, ephemeral token that requires zero maintenance.

However, only a project owner on PyPI can do that and it seems that Syrus is currently the sole owner.

Pinging @syrusakbary - can you make the switch or increase the bus factor by adding me as owner (I'm only registered as maintainer, but that is not sufficient to make the switch)?

Metadata

Metadata

Assignees

No one assigned

    Labels

    securityFor security critical issues

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions