Skip to content

Use trusted publishing#1157

Open
madig wants to merge 1 commit intomainfrom
use-trusted-publishing
Open

Use trusted publishing#1157
madig wants to merge 1 commit intomainfrom
use-trusted-publishing

Conversation

@madig
Copy link
Copy Markdown
Collaborator

@madig madig commented Sep 22, 2025

In light of the recent npm supply chain attacks and also https://blog.pypi.org/posts/2025-09-16-github-actions-token-exfiltration/, I'm combing through our font stack to see if all them Py projects are using the trusted publisher mechanism as recommended by PyPI. See https://docs.pypi.org/trusted-publishers/ and https://docs.astral.sh/uv/guides/integration/github/#publishing-to-pypi.

Someone needs to do two things for this PR to work:

I'm not sure if one needs to do anything to make twine pick up the new creds, trusted publishing should be supported in v6.1.0.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant