Skip to content

Security: Finish PyPI Trusted Publisher binding (OIDC) #45

Description

@caidurbin

What to build

Complete the tokenless PyPI publishing lane. The workflow already publishes via OIDC Trusted Publishing with PEP 740 attestations on by default; what's missing is the PyPI-side binding (project + repo + workflow + environment). Verify current state first — this may have been partially completed under closed #24/#30 — then finish or confirm the binding so v*-tag releases publish with no stored API token.

Acceptance criteria

Blocked by

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions