Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

How does PyPI decide to trust the github action to issue the short lived token?

Do you use the Github token to exchange for the PyPI token?



That process is described in the user documentation[1]: a project can have publishers added to it on PyPI's website, with each publishers' configuration specifying the necessary state for a trust relationship with a particular workflow in a particular GitHub repository.

[1]: https://docs.pypi.org/trusted-publishers/adding-a-publisher/




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: