Stop storing PyPI API tokens in CI: use trusted publishing with OIDC
Long-lived PyPI tokens in CI are a standing risk. Trusted publishing uses OIDC claims to grant short-lived upload rights without storing secrets.
ReadMeFeed / Community knowledge
Real questions. Useful conversations. Find the people who know your stack.
Long-lived PyPI tokens in CI are a standing risk. Trusted publishing uses OIDC claims to grant short-lived upload rights without storing secrets.