Elektrine lite

← Feed

@matthiask@hachyderm.io

Post #850630

2026-03-27 08:32 UTC

The malicious releases uploaded to PyPI and the blog post by Brett Cannon https://snarky.ca/why-pylock-toml-includes-digital-attestations/ finally motivated me to delete all PyPI tokens I still had. Now I forced myself to switch to trusted publishing for all future releases. The latest django-prose-editor patch release has already used trusted publishing. It wasn't hard, I just needed a reason and some handholding to do it.

Replies (0)

No replies.