Skip to content

[TODO] Migrate the release process to Trusted Publishing #2147

Open
@webknjaz

Description

@webknjaz

This will enable publishing digital attestations and using short-lived secrets.

If implemented right, this will preserve the ability for release managers to verify the dists before publishing them.

https://packaging.python.org/en/latest/guides/publishing-package-distribution-releases-using-github-actions-ci-cd-workflows/ shows how to do this.

Metadata

Metadata

Labels

ciRelated to continuous integration tasksmaintenanceRelated to maintenance processespackagingPackaging related stuffrefactorRefactoring code

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions