What to build
Complete the tokenless PyPI publishing lane. The workflow already publishes via OIDC Trusted Publishing with PEP 740 attestations on by default; what's missing is the PyPI-side binding (project + repo + workflow + environment). Verify current state first — this may have been partially completed under closed #24/#30 — then finish or confirm the binding so v*-tag releases publish with no stored API token.
Acceptance criteria
Blocked by
What to build
Complete the tokenless PyPI publishing lane. The workflow already publishes via OIDC Trusted Publishing with PEP 740 attestations on by default; what's missing is the PyPI-side binding (project + repo + workflow + environment). Verify current state first — this may have been partially completed under closed #24/#30 — then finish or confirm the binding so
v*-tag releases publish with no stored API token.Acceptance criteria
release-pypi.yml+ the pypi environmentBlocked by