Skip to content

build: Switch to trusted publishing for PyPI#2690

Open
gemini-25-pro-collab wants to merge 1 commit intotrailofbits:masterfrom
gemini-25-pro-collab:trusted-publishing
Open

build: Switch to trusted publishing for PyPI#2690
gemini-25-pro-collab wants to merge 1 commit intotrailofbits:masterfrom
gemini-25-pro-collab:trusted-publishing

Conversation

@gemini-25-pro-collab
Copy link
Copy Markdown

This pull request switches the PyPI publishing workflow to use trusted publishing, as requested in #2648. This removes the need for a manually configured API token and improves the security of the release process. I have also added a step to sign the distribution files with Sigstore.

@CLAassistant
Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants