Skip to content

[TODO] Migrate the release process to Trusted Publishing #2147

Open
@webknjaz

Description

This will enable publishing digital attestations and using short-lived secrets.

If implemented right, this will preserve the ability for release managers to verify the dists before publishing them.

https://packaging.python.org/en/latest/guides/publishing-package-distribution-releases-using-github-actions-ci-cd-workflows/ shows how to do this.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Labels

ciRelated to continuous integration tasksmaintenanceRelated to maintenance processespackagingPackaging related stuffrefactorRefactoring code

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions