#trustedpublishers β Public Fediverse posts
Live and recent posts from across the Fediverse tagged #trustedpublishers, aggregated by home.social.
-
Its a bit weird that #GitHub spearheaded #OIDC based authentication to retrieve short lived tokens for cloud platforms and then #PyPi, #RubyGems and even #Dart went and used that to enable short lived tokens for publishing packages β but GitHub themselves haven't yet launched it for #npm
@openssf has even launched a #TrustedPublishers guideline: https://repos.openssf.org/trusted-publishers-for-all-package-repositories
https://blog.rubygems.org/2023/12/14/trusted-publishing.html
-
Its a bit weird that #GitHub spearheaded #OIDC based authentication to retrieve short lived tokens for cloud platforms and then #PyPi, #RubyGems and even #Dart went and used that to enable short lived tokens for publishing packages β but GitHub themselves haven't yet launched it for #npm
@openssf has even launched a #TrustedPublishers guideline: https://repos.openssf.org/trusted-publishers-for-all-package-repositories
https://blog.rubygems.org/2023/12/14/trusted-publishing.html
-
Its a bit weird that #GitHub spearheaded #OIDC based authentication to retrieve short lived tokens for cloud platforms and then #PyPi, #RubyGems and even #Dart went and used that to enable short lived tokens for publishing packages β but GitHub themselves haven't yet launched it for #npm
@openssf has even launched a #TrustedPublishers guideline: https://repos.openssf.org/trusted-publishers-for-all-package-repositories
https://blog.rubygems.org/2023/12/14/trusted-publishing.html
-
Its a bit weird that #GitHub spearheaded #OIDC based authentication to retrieve short lived tokens for cloud platforms and then #PyPi, #RubyGems and even #Dart went and used that to enable short lived tokens for publishing packages β but GitHub themselves haven't yet launched it for #npm
@openssf has even launched a #TrustedPublishers guideline: https://repos.openssf.org/trusted-publishers-for-all-package-repositories
https://blog.rubygems.org/2023/12/14/trusted-publishing.html
-
Just released: #cherry_picker 2.3.0 π
This tool creates backports for CPython when the Miss Islington bot can't, usually due to a merge conflict.
π Add support for #Python 3.13, drop EOL 3.8
π Resolve usernames when remote ends with a trailing slash
π Optimize validate_sha() with --max-count=1
π Remove multiple commit prefixes
π Handle whitespace when calculating usernames
π Publish to PyPI using #TrustedPublishers
π Generate #PEP740 attestations
π And more! -
Just released: #cherry_picker 2.3.0 π
This tool creates backports for CPython when the Miss Islington bot can't, usually due to a merge conflict.
π Add support for #Python 3.13, drop EOL 3.8
π Resolve usernames when remote ends with a trailing slash
π Optimize validate_sha() with --max-count=1
π Remove multiple commit prefixes
π Handle whitespace when calculating usernames
π Publish to PyPI using #TrustedPublishers
π Generate #PEP740 attestations
π And more! -
Just released: #cherry_picker 2.3.0 π
This tool creates backports for CPython when the Miss Islington bot can't, usually due to a merge conflict.
π Add support for #Python 3.13, drop EOL 3.8
π Resolve usernames when remote ends with a trailing slash
π Optimize validate_sha() with --max-count=1
π Remove multiple commit prefixes
π Handle whitespace when calculating usernames
π Publish to PyPI using #TrustedPublishers
π Generate #PEP740 attestations
π And more! -
Just released: #cherry_picker 2.3.0 π
This tool creates backports for CPython when the Miss Islington bot can't, usually due to a merge conflict.
π Add support for #Python 3.13, drop EOL 3.8
π Resolve usernames when remote ends with a trailing slash
π Optimize validate_sha() with --max-count=1
π Remove multiple commit prefixes
π Handle whitespace when calculating usernames
π Publish to PyPI using #TrustedPublishers
π Generate #PEP740 attestations
π And more! -
π₯π°ππ Exciting!
I'm doing the first @pillow release using cibuildwheel + PyPI publish GitHub Action + Trusted Publishers!
It'll take just under three hours to build 68 wheels and an sdist, and then upload them automatically to @pypi π€
The matrix covers CPython 3.8-3.12, PyPy 3.9-3.10, manylinux, musllinux, macOS Intel + Apple Silicon, Windows 32-bit + 64-bit + ARM...
Follow along the Easter fun at https://github.com/python-pillow/Pillow/actions/runs/8506382482 !
#Python #Pillow #PythonPillow #PyPI #TrustedPublishers #cibuildwheel
-
π₯π°ππ Exciting!
I'm doing the first @pillow release using cibuildwheel + PyPI publish GitHub Action + Trusted Publishers!
It'll take just under three hours to build 68 wheels and an sdist, and then upload them automatically to @pypi π€
The matrix covers CPython 3.8-3.12, PyPy 3.9-3.10, manylinux, musllinux, macOS Intel + Apple Silicon, Windows 32-bit + 64-bit + ARM...
Follow along the Easter fun at https://github.com/python-pillow/Pillow/actions/runs/8506382482 !
#Python #Pillow #PythonPillow #PyPI #TrustedPublishers #cibuildwheel
-
π₯π°ππ Exciting!
I'm doing the first @pillow release using cibuildwheel + PyPI publish GitHub Action + Trusted Publishers!
It'll take just under three hours to build 68 wheels and an sdist, and then upload them automatically to @pypi π€
The matrix covers CPython 3.8-3.12, PyPy 3.9-3.10, manylinux, musllinux, macOS Intel + Apple Silicon, Windows 32-bit + 64-bit + ARM...
Follow along the Easter fun at https://github.com/python-pillow/Pillow/actions/runs/8506382482 !
#Python #Pillow #PythonPillow #PyPI #TrustedPublishers #cibuildwheel
-
π₯π°ππ Exciting!
I'm doing the first @pillow release using cibuildwheel + PyPI publish GitHub Action + Trusted Publishers!
It'll take just under three hours to build 68 wheels and an sdist, and then upload them automatically to @pypi π€
The matrix covers CPython 3.8-3.12, PyPy 3.9-3.10, manylinux, musllinux, macOS Intel + Apple Silicon, Windows 32-bit + 64-bit + ARM...
Follow along the Easter fun at https://github.com/python-pillow/Pillow/actions/runs/8506382482 !
#Python #Pillow #PythonPillow #PyPI #TrustedPublishers #cibuildwheel
-
Exciting news from #PyPI, just in time for @PyConUS:
"Starting today, PyPI package maintainers can adopt a new, more secure publishing method that does not require long-lived passwords or API tokens to be shared with external systems."
I've been part of the private beta and it works really well!
https://blog.pypi.org/posts/2023-04-20-introducing-trusted-publishers/
-
Exciting news from #PyPI, just in time for @PyConUS:
"Starting today, PyPI package maintainers can adopt a new, more secure publishing method that does not require long-lived passwords or API tokens to be shared with external systems."
I've been part of the private beta and it works really well!
https://blog.pypi.org/posts/2023-04-20-introducing-trusted-publishers/
-
Exciting news from #PyPI, just in time for @PyConUS:
"Starting today, PyPI package maintainers can adopt a new, more secure publishing method that does not require long-lived passwords or API tokens to be shared with external systems."
I've been part of the private beta and it works really well!
https://blog.pypi.org/posts/2023-04-20-introducing-trusted-publishers/
-
Exciting news from #PyPI, just in time for @PyConUS:
"Starting today, PyPI package maintainers can adopt a new, more secure publishing method that does not require long-lived passwords or API tokens to be shared with external systems."
I've been part of the private beta and it works really well!
https://blog.pypi.org/posts/2023-04-20-introducing-trusted-publishers/