Skip to content

build: enable Trusted Publishing to PyPI#157

Merged
tokoko merged 1 commit intomainfrom
vbarua/configure-trusted-publishing
Mar 15, 2026
Merged

build: enable Trusted Publishing to PyPI#157
tokoko merged 1 commit intomainfrom
vbarua/configure-trusted-publishing

Conversation

@vbarua
Copy link
Member

@vbarua vbarua commented Mar 13, 2026

No description provided.

@vbarua
Copy link
Member Author

vbarua commented Mar 13, 2026

In the process of working on substrait-packaging, I learnt about PyPI trusted publishing.

I've configured the publisher in PyPI associated with the release.yml workflow
Screenshot 2026-03-13 at 12 36 39

Using this, we can avoid having to persists a long-lived token, and it gives users a better guarantee that the package they are installing was generated from a CI job.

@vbarua vbarua marked this pull request as ready for review March 13, 2026 19:38
Copy link
Contributor

@tokoko tokoko left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nice

@tokoko tokoko merged commit 3e4f8c5 into main Mar 15, 2026
20 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants