Skip to content

Publish to PyPI via trusted publishing - #116

Open
isayev wants to merge 1 commit into
mainfrom
ci/pypi-trusted-publishing
Open

Publish to PyPI via trusted publishing#116
isayev wants to merge 1 commit into
mainfrom
ci/pypi-trusted-publishing

Conversation

@isayev

@isayev isayev commented Aug 7, 2026

Copy link
Copy Markdown
Contributor

Switches the release publish step from the long-lived PYPI_TOKEN secret to PyPI Trusted Publishing (OIDC): the publish job gets id-token: write and uv publish --trusted-publishing always replaces the token flag.

Merge prerequisite: on PyPI, the aimnet project must first have a trusted publisher registered (GitHub, owner isayevlab, repository aimnetcentral, workflow on-release-main.yml, no environment) — requires the project owner. A second project owner should be added at the same time.

The PYPI_TOKEN secret stays untouched as a manual fallback; delete it after the first successful OIDC publish.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant