Followup from https://github.com/jupyterhub/team-compass/issues/763#issuecomment-2751557550 Audit all PyPI packages under Jupyter to see: - which ones are using a trusted publisher https://docs.pypi.org/trusted-publishers/using-a-publisher/ - which ones are using tokens, and when the token was last updated - which ones are using trusted publisher but still have old tokens that should be deleted