Re: Using Github Actions Trusted Publisher for PyPI releases ?

2024-06-25 Thread Jarek Potiuk
> > > A quick read includes that these reviewers can include teams which I > interpret as it can easily be the whole of the PMC who have linked to a > GitHub account. > I will explore it in detail when we will set it up. > > I wonder if a future enhancement would be to use an API to connect to th

Re: Using Github Actions Trusted Publisher for PyPI releases ?

2024-06-25 Thread Dave Fisher
> On Jun 25, 2024, at 12:54 AM, Jarek Potiuk wrote: > > FYI. I created a proposal [1] in Airflow to switch to the Trusted Publisher > workflow and providing consensus, we will implement it. This is cool. > > BTW. Interesting finding - I found out while reading docs, that it's > recommended t

Re: Using Github Actions Trusted Publisher for PyPI releases ?

2024-06-25 Thread Jarek Potiuk
FYI. I created a proposal [1] in Airflow to switch to the Trusted Publisher workflow and providing consensus, we will implement it. BTW. Interesting finding - I found out while reading docs, that it's recommended to use separate "Github Actions Environment" for such trusted publishing workflows, w