-
-
Notifications
You must be signed in to change notification settings - Fork 146
Switch to trusted publishing #263
Copy link
Copy link
Open
Labels
securityFor security critical issuesFor security critical issues
Description
We should switch to Trusted Publishing for our releases. Trusted publishing replaces a persistent secret that can leak with a cryptographically scoped, ephemeral token that requires zero maintenance.
However, only a project owner on PyPI can do that and it seems that Syrus is currently the sole owner.
Pinging @syrusakbary - can you make the switch or increase the bus factor by adding me as owner (I'm only registered as maintainer, but that is not sufficient to make the switch)?
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
securityFor security critical issuesFor security critical issues