jaraco / jaraco/jaraco.functools

Use Trusted Publishing to upload to PyPI

Open
#37 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
22
Forks
16
PR merge metrics
No merged PRs in 30d

Description

I'm looking at reducing the risk of supply chain attacks on my project, which has this as a dependency.
For details, see https://pydevtools.com/handbook/explanation/why-use-trusted-publishing-for-pypi/

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reviewing the linked Trusted Publishing guidance and the repository's existing PyPI upload process; the issue does not name a file or workflow. Done means the project can upload its Python package to PyPI using Trusted Publishing and no longer relies on the current publishing credentials.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
release
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.