common-workflow-language / common-workflow-language/cwl-upgrader

Use Trusted Publishing to upload to PyPI

Open
#211 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
7
Forks
4
Avg merge
11h 6m
Merged PRs (30d)
1

Description

To provide PEP 740 attestations: https://trailofbits.github.io/are-we-pep740-yet/
and reduce the risk of supply chain attacks.
For details, see https://pydevtools.com/handbook/explanation/why-use-trusted-publishing-for-pypi/

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reading the PEP 740 overview and the linked Trusted Publishing explanation. Then locate the repository's existing package-publishing entry point and determine how it can provide attestations without long-lived credentials; done means releases use Trusted Publishing and produce PEP 740 attestations. No specific file or test is named in the issue.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
release
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.