Post #2869144
2025-11-26 21:11 UTC
@miketheman@hachyderm.io .. or you could *not* trust a third party to publish to PyPI for you.
Replies (1)
-
@miketheman@hachyderm.io 2025-11-26 21:25
@kaleissin@wandering.shop yes, that's also one approach, which assumes you have another way to secure long-lived credentials instead of trusting a third party to generate a short-lived, minimally scoped token. Teams that publish from a CI/CD provider have a better option than storing long-lived tokens.