File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change 11name : Release
22
3+ # IMPORTANT: PyPI validates against the filename (release.yml),
4+ # the owner, and the repo registered in the Trusted Publisher. If you change
5+ # the filename, update the registration on pypi.org.
36on :
47 push :
58 tags :
1417 release :
1518 runs-on : ubuntu-latest
1619 timeout-minutes : 20
20+ environment : pypi # Must exist in GitHub AND be registered in PyPI
1721 permissions :
22+ id-token : write # OIDC: mandatory for Trusted Publishing
1823 contents : read
1924
2025 steps :
@@ -36,11 +41,10 @@ jobs:
3641 - name : Build distribution
3742 run : python -m build --sdist --wheel
3843
39- # Recommended future improvement: migrate to Trusted Publishing (OIDC).
40- # Requires: permissions: id- token: write, remove 'password',
41- # and configure the publisher on pypi.org .
44+ # Trusted Publishing: no password required. The action obtains an ephemeral
45+ # OIDC token signed by GitHub, which PyPI validates against the
46+ # registered publisher. There are no secrets to rotate or leak .
4247 - name : Publish to PyPI
4348 if : startsWith(github.ref, 'refs/tags/')
4449 uses : pypa/gh-action-pypi-publish@release/v1
45- with :
46- password : ${{ secrets.PYPI_API_TOKEN }}
50+ # attestations: true # optional: generate PEP 740 attestations (supply chain)
You can’t perform that action at this time.
0 commit comments