Skip to content

Commit fdca315

Browse files
Enhance release workflow: add environment and permissions for Trusted Publishing
Signed-off-by: kmilo <kmilo.denis.glez@yandex.com>
1 parent 30170b7 commit fdca315

1 file changed

Lines changed: 9 additions & 5 deletions

File tree

‎.github/workflows/release.yml‎

Lines changed: 9 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,8 @@
11
name: Release
22

3+
# IMPORTANT: PyPI validates against the filename (release.yml),
4+
# the owner, and the repo registered in the Trusted Publisher. If you change
5+
# the filename, update the registration on pypi.org.
36
on:
47
push:
58
tags:
@@ -14,7 +17,9 @@ jobs:
1417
release:
1518
runs-on: ubuntu-latest
1619
timeout-minutes: 20
20+
environment: pypi # Must exist in GitHub AND be registered in PyPI
1721
permissions:
22+
id-token: write # OIDC: mandatory for Trusted Publishing
1823
contents: read
1924

2025
steps:
@@ -36,11 +41,10 @@ jobs:
3641
- name: Build distribution
3742
run: python -m build --sdist --wheel
3843

39-
# Recommended future improvement: migrate to Trusted Publishing (OIDC).
40-
# Requires: permissions: id-token: write, remove 'password',
41-
# and configure the publisher on pypi.org.
44+
# Trusted Publishing: no password required. The action obtains an ephemeral
45+
# OIDC token signed by GitHub, which PyPI validates against the
46+
# registered publisher. There are no secrets to rotate or leak.
4247
- name: Publish to PyPI
4348
if: startsWith(github.ref, 'refs/tags/')
4449
uses: pypa/gh-action-pypi-publish@release/v1
45-
with:
46-
password: ${{ secrets.PYPI_API_TOKEN }}
50+
# attestations: true # optional: generate PEP 740 attestations (supply chain)

0 commit comments

Comments
 (0)