amarna icon indicating copy to clipboard operation
amarna copied to clipboard

Switch to trusted publishing

Open woodruffw opened this issue 1 year ago • 0 comments

All of our PyPI-packaged projects should use trusted publishing, rather than a manually configured API token.

Example trusted publishing workflow:

https://github.com/trailofbits/blight/blob/master/.github/workflows/release.yml

Resources:

  • https://docs.pypi.org/trusted-publishers/
  • https://packaging.python.org/en/latest/guides/publishing-package-distribution-releases-using-github-actions-ci-cd-workflows/

woodruffw avatar Sep 29 '23 20:09 woodruffw