Skip to content

security stuff#41

Open
kevinjqliu wants to merge 6 commits intomainfrom
kevinjqliu/security-improvements
Open

security stuff#41
kevinjqliu wants to merge 6 commits intomainfrom
kevinjqliu/security-improvements

Conversation

@kevinjqliu
Copy link
Copy Markdown
Owner

Rationale for this change

Are these changes tested?

Are there any user-facing changes?

Co-authored-by: Copilot <copilot@github.com>
Copy link
Copy Markdown

@gemini-code-assist gemini-code-assist Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the Dependabot configuration to group minor and patch updates, introduces a comprehensive security policy, and updates the release documentation to reflect the transition from manual twine uploads to automated GitHub Actions using Trusted Publishing and PEP 740 build attestations. The review feedback focuses on improving the release guide by including source distributions in the artifact examples and ensuring consistent casing for 'PyPI' throughout the document.

Comment thread mkdocs/docs/how-to-release.md Outdated
Comment thread mkdocs/docs/how-to-release.md Outdated
kevinjqliu and others added 5 commits May 2, 2026 13:00
Co-authored-by: Copilot <copilot@github.com>
Co-authored-by: Copilot <copilot@github.com>
Co-authored-by: Copilot <copilot@github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant