Audit all Jupyter PyPI package tokens
- Dominant language
- Jupyter Notebook
- Stars
- 27
- Forks
- 12
- Avg merge
- 3d 5h
- Merged PRs (30d)
- 3
Description
Followup from https://github.com/jupyterhub/team-compass/issues/763#issuecomment-2751557550
Audit all PyPI packages under Jupyter to see:
- which ones are using a trusted publisher https://docs.pypi.org/trusted-publishers/using-a-publisher/
- which ones are using tokens, and when the token was last updated
- which ones are using trusted publisher but still have old tokens that should be deleted
Contributor guide
No contributing guide indexed for this repository
Research direction
Start with the linked team-compass follow-up and PyPI's trusted publishers documentation. Inventory Jupyter's PyPI packages, recording trusted-publisher use, token use, and token update dates; identify old tokens that should be deleted. Done when the full audit and deletion candidates are documented.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- jupyter-notebook, python
- Domain
- security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100