Post #850630
2026-03-27 08:32 UTC
The malicious releases uploaded to PyPI and the blog post by Brett Cannon
https://snarky.ca/why-pylock-toml-includes-digital-attestations/ finally motivated me to delete all PyPI tokens I still had. Now I forced myself to switch to trusted publishing for all future releases. The latest django-prose-editor patch release has already used trusted publishing. It wasn't hard, I just needed a reason and some handholding to do it.
Replies (0)
No replies.