From 6fd73bbf6157416e7a11ca8b18bd4184846092c2 Mon Sep 17 00:00:00 2001 From: Paul Romano Date: Thu, 27 Apr 2023 07:05:03 -0500 Subject: [PATCH] Change PyPI release workflow to use trusted publishing --- .github/workflows/publish-pypi.yml | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/.github/workflows/publish-pypi.yml b/.github/workflows/publish-pypi.yml index ffe394fc..cf01afee 100644 --- a/.github/workflows/publish-pypi.yml +++ b/.github/workflows/publish-pypi.yml @@ -7,6 +7,8 @@ on: jobs: deploy: runs-on: ubuntu-latest + permissions: + id-token: write steps: - uses: actions/checkout@v2 - name: Set up Python @@ -21,6 +23,3 @@ jobs: run: python -m build - name: Publish a Python distribution to PyPI uses: pypa/gh-action-pypi-publish@release/v1 - with: - user: __token__ - password: ${{ secrets.PYPI_API_TOKEN }}