-
-
Notifications
You must be signed in to change notification settings - Fork 629
Closed
Labels
ciRelated to continuous integration tasksRelated to continuous integration tasksmaintenanceRelated to maintenance processesRelated to maintenance processespackagingPackaging related stuffPackaging related stuffrefactorRefactoring codeRefactoring code
Description
This will enable publishing digital attestations and using short-lived secrets.
If implemented right, this will preserve the ability for release managers to verify the dists before publishing them.
https://packaging.python.org/en/latest/guides/publishing-package-distribution-releases-using-github-actions-ci-cd-workflows/ shows how to do this.
hugovk
Metadata
Metadata
Labels
ciRelated to continuous integration tasksRelated to continuous integration tasksmaintenanceRelated to maintenance processesRelated to maintenance processespackagingPackaging related stuffPackaging related stuffrefactorRefactoring codeRefactoring code