Skip to content

Commit 69c7d47

Browse files
lwasserwebknjaz
andcommitted
fix: edits from @webknjaz
Co-authored-by: 🇺🇦 Sviatoslav Sydorenko (Святослав Сидоренко) <[email protected]>
1 parent 5505fef commit 69c7d47

File tree

1 file changed

+5
-0
lines changed

1 file changed

+5
-0
lines changed

_posts/2024-12-13-python-packaging-security.md

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -49,8 +49,13 @@ The Ultralytics breach is a wake-up call for all maintainers: secure your workfl
4949
- Delete old GitHub tokens that you are no longer using. And Refresh existing tokens that you need periodically.
5050

5151
### Strengthen PyPI security
52+
<<<<<<< HEAD
5253
- 🔑 Set up Trusted Publisher for tokenless authentication with PyPI.
5354
- Make sure you store recovery codes securely for PyPI 2-factor authentication (2FA).
55+
=======
56+
- 🔑 Set up Trusted Publisher for tokenless authentication with PyPI and **always** set the validated environment in it.
57+
- 📱 Enable 2FA for your PyPI account and store recovery codes securely.
58+
>>>>>>> 029bd04 (fix: edits from @webknjaz)
5459
5560
These steps will significantly reduce risks to your packages, contributors, and the broader Python ecosystem. Don’t wait—start securing your workflows today.
5661
</div>

0 commit comments

Comments
 (0)