common-workflow-language / common-workflow-language/cwl-upgrader
Use Trusted Publishing to upload to PyPI
- Dominant language
- Python
- Stars
- 7
- Forks
- 4
- Avg merge
- 11h 6m
- Merged PRs (30d)
- 1
Description
To provide PEP 740 attestations: https://trailofbits.github.io/are-we-pep740-yet/
and reduce the risk of supply chain attacks.
For details, see https://pydevtools.com/handbook/explanation/why-use-trusted-publishing-for-pypi/
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by reading the PEP 740 overview and the linked Trusted Publishing explanation. Then locate the repository's existing package-publishing entry point and determine how it can provide attestations without long-lived credentials; done means releases use Trusted Publishing and produce PEP 740 attestations. No specific file or test is named in the issue.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- python
- Domain
- release
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 45/100