Starting 2023-04-20, PyPI package maintainers can adopt a OIDC authentication mechanism.
https://blog.pypi.org/posts/2023-04-20-introducing-trusted-publishers/
DOD: We should try this feature and if it fits our ci/cd scenarios, we should use it in all build pipelines that publishes packages to public package index.