6 ms·
If you're using GHA to publish then you still need a trusted branch to provide secrets to. If you're not publishing using CI, then you can still upload to PyPI
by Bognar 3y ago
If you're using GHA to publish then you still need a trusted branch to provide secrets to. If you're not publishing using CI, then you can still upload to PyPI manually with an API Token.
> without needing to give microsoft total access to uploading to pypi
I assume you're referring to Trusted Publishers here? It's a per-project configuration using the industry standard of OIDC that you don't have to opt in to, so "total access" is a silly characterization. Also if you're insinuating that MS is going to generate fraudulent OIDC tokens to compromise a PyPI package, then you might want to start weaning yourself off the kool-aid.
- LtWorf 3y ago> If you're using GHA to publish then you still need a trusted branch to provide secrets to The vulnerability was exactly that the secrets of the trusted branch can get leaked :) > you can still upload to PyPI manually with an API Token I can, BUT if you want to be a Trusted Publisher™ the only way is to do it via github. https://docs.pypi.org/trusted-publishers/ https://docs.pypi.org/trusted-publishers/ Most likely the plan is to make it compulsory for all projects eventually, just like they made 2fa compulsory. So less secure is considered as MORE secure by pypi :) Which is consistent with the idea that no PGP signature is more secure than signed uploads. Or the idea that a global token in a clear text file is somehow safer than a password that gets typed every time.