pypa / pypa/packaging.python.org
Recommend using project-scoped API access tokens for dist uploads
Nobody has claimed this yet.
- Dominant language
- Python
- Stars
- 1.7k
- Forks
- 1.7k
- Avg merge
- 3d 12h
- Merged PRs (30d)
- 4
Description
Ref: https://github.com/pypa/warehouse/issues/6211#issuecomment-513102869
The distributing guide should now mention the possibility of getting access tokens on a per-project basis and recommend that for use at least in automatic CI/CD systems: https://packaging.python.org/guides/distributing-packages-using-setuptools/#create-an-account
Also: @Ewjoachim brought up a question about storing multiple tokens
https://twitter.com/Ewjoachim/status/1154474823717982208. This should probably be also clearly answered in docs.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the distributing guide section linked in the issue and review the referenced Warehouse discussion and question about storing multiple tokens. Update the documentation to recommend project-scoped tokens for automated CI/CD uploads and clearly explain how multiple tokens should be handled.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- python
- Domain
- documentation
- Issue type
- Documentation
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100