Skip to content

Restrict OIDC token to publish job#249

Merged
miketheman merged 1 commit into
pypa:mainfrom
trail-of-forks:ft/release-oidc-publish-job
Jun 1, 2026
Merged

Restrict OIDC token to publish job#249
miketheman merged 1 commit into
pypa:mainfrom
trail-of-forks:ft/release-oidc-publish-job

Conversation

@facutuesca
Copy link
Copy Markdown
Contributor

The GH OIDC token used for Trusted Publishing should not be available to non-publishing steps. This PR removes it from the steps that install the dependencies and build the project, so that it's only available during PyPI publishing.

cc @miketheman

@miketheman miketheman merged commit 71cb041 into pypa:main Jun 1, 2026
1 check passed
@facutuesca facutuesca deleted the ft/release-oidc-publish-job branch June 1, 2026 20:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants