Skip to content

Publish to PyPI using OIDC trusted publishing #1232

@Strift

Description

@Strift

The workflow uploads with TWINE_USERNAME: __token__ and TWINE_PASSWORD: "pypi-${{ secrets.PYPI_API_TOKEN }}", which requires a long-lived secret; using PyPI Trusted Publishing (OIDC) would avoid secret injection and reduce exposure/rotation burden.

Metadata

Metadata

Assignees

No one assigned

    Labels

    maintenanceAnything related to maintenance (CI, tests, refactoring...)

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions