From 38dedab0cb832429fccddfbe44ee57434b152543 Mon Sep 17 00:00:00 2001 From: Ilya Konstantinov Date: Thu, 20 Apr 2023 21:39:50 -0400 Subject: [PATCH] Switch from pypi token to GitHub as trusted publisher --- .github/workflows/release.yaml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index db5220f3..9591432e 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -11,6 +11,8 @@ on: jobs: deploy: runs-on: ubuntu-latest + permissions: + id-token: write steps: - uses: actions/checkout@v3 - name: Set up Python @@ -30,8 +32,6 @@ jobs: - name: Publish to PyPI uses: pypa/gh-action-pypi-publish@release/v1 if: ${{ github.event_name == 'release' }} - with: - password: ${{ secrets.PYPI_API_TOKEN }} - name: Publish to Test PyPI uses: pypa/gh-action-pypi-publish@release/v1