Matthias K
matthiask@hachyderm.io
<p>Interested in social justice, climate, against cars and general stupidity. Programming for the good.</p><p>He/him. </p><p>Programmer, gardener, cyclist and dad by day.</p><p>I (help) maintain a few <a href="https://hachyderm.io/tags/Django" class="mention hashtag" rel="tag">#<span>Django</span></a> packages such as django-debug-toolbar, html-sanitizer and others.</p>
Posts
-
Post #850630
The malicious releases uploaded to PyPI and the blog post by Brett Cannon https://snarky.ca/why-pylock-toml-includes-digital-attestations/ finally motivated me to delete all PyPI tokens I still had. Now I forced myself to switch to trusted publishing for all future releases. The latest django-prose-editor patch release has already used trusted publishing. It wasn&#39;t hard, I just needed a reason and some handholding to do it.