pypa / pypa/packaging.python.org

Update "Packaging Python Projects" tutorial to tell users to prefer Trusted publishing over API tokens

Open
#1,888 4 comments 2 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
1.7k
Forks
1.7k
Avg merge
3d 12h
Merged PRs (30d)
4

Description

Issue Description

https://packaging.python.org/en/latest/tutorials/packaging-projects/#uploading-the-distribution-archives should tell users to prefer Trusted Publishing over API tokens, and point users towards https://packaging.python.org/en/latest/guides/publishing-package-distribution-releases-using-github-actions-ci-cd-workflows/

Code of Conduct
  • I am aware that participants in this repository must follow the PSF Code of Conduct.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the “Uploading the distribution archives” section in the Packaging Python Projects tutorial and review the linked guide on publishing releases with GitHub Actions. Update the tutorial to recommend Trusted Publishing over API tokens and link to that guide. Done means the section clearly communicates the preferred workflow and the new guide is linked.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
documentation
Issue type
Documentation
Difficulty
1/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
55/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.