Skip to content

Use a trusted publisher to release versions #279

Description

@c-w-feldmann

From the pypi docs: https://docs.pypi.org/trusted-publishers/

Security: PyPI's normal API tokens are long-lived, meaning that an attacker who compromises a package's release token can use it until its legitimate user notices and manually revokes it. Trusted Publishing avoids this problem because the tokens minted expire automatically.

Metadata

Metadata

Assignees

Labels

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions