Skip to content

[CD advice] Publishing Python packages #30

Description

@webknjaz

Hey, I noticed that python-publish.yml uses a number of outdated practices that is best to fix:

  1. A long-living API token is used — get rid of it and replace with secretless publishing; my PyPUG guide is already updated to guide you through this: https://packaging.python.org/en/latest/guides/publishing-package-distribution-releases-using-github-actions-ci-cd-workflows/
  2. Building in the publishing job is a security concern as it enlarges the attack surface; the same guide shows how to fix this with reduced privileges; this is especially important with secretless publishing
  3. Using --sdist --wheel together causes pypa/build make dists separately, from the Git checkout; the best practice to smoke-test what pip would actually do is to drop them; this will make it build sdist from Git, but wheel from that sdist

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions