Commit d135615
committed
Use trusted-publishing instead of long-lived token
Run job under an environment called 'pypi', set permissions: id-token: write, and don't use PYPI_TOKEN upload. Xref https://github.com/pypa/gh-action-pypi-publish/tree/v1.14.0?tab=readme-ov-file#trusted-publishing.1 parent c97a929 commit d135615
1 file changed
Lines changed: 10 additions & 4 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
62 | 62 | | |
63 | 63 | | |
64 | 64 | | |
65 | | - | |
| 65 | + | |
| 66 | + | |
66 | 67 | | |
67 | | - | |
| 68 | + | |
68 | 69 | | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
69 | 76 | | |
70 | 77 | | |
71 | 78 | | |
| |||
75 | 82 | | |
76 | 83 | | |
77 | 84 | | |
78 | | - | |
79 | | - | |
| 85 | + | |
80 | 86 | | |
0 commit comments