Skip to content

Use trusted publisher for PyPI releases #1754

@trallard

Description

@trallard

We use the publish.yaml workflow for PST releases.

This still uses a token for this action, though trusted publishing is now encouraged over API tokens as a best practice on supported platforms (like GitHub).

To do this, we would need to:

  • Update publish.yaml - I can do this
  • Update the settings in the PyPI package to enable trusted publishers. I'm not sure who has access to this, but maybe @choldgraf (?).
  • Remove the existing token from GH

Ref: https://docs.pypi.org/trusted-publishers/adding-a-publisher/

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions