From e5036d8d7e37619fa9cb0d1e39a369e50e7d2457 Mon Sep 17 00:00:00 2001 From: Martin Pitt Date: Sun, 24 Dec 2023 22:23:51 +0100 Subject: [PATCH] workflows: Move from static PyPI token to trusted publisher See https://docs.pypi.org/trusted-publishers/adding-a-publisher/ --- .github/workflows/release.yml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index fd4303f4..3960d4e3 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -7,6 +7,9 @@ on: jobs: release: runs-on: ubuntu-22.04 + environment: release + permissions: + id-token: write steps: - name: Clone repository uses: actions/checkout@v3 @@ -46,6 +49,3 @@ jobs: - name: Create PyPy release uses: pypa/gh-action-pypi-publish@release/v1 - with: - user: __token__ - password: ${{ secrets.PYPI_API_TOKEN }}