home.social

#trustedpublishers β€” Public Fediverse posts

Live and recent posts from across the Fediverse tagged #trustedpublishers, aggregated by home.social.

fetched live
  1. Its a bit weird that #GitHub spearheaded #OIDC based authentication to retrieve short lived tokens for cloud platforms and then #PyPi, #RubyGems and even #Dart went and used that to enable short lived tokens for publishing packages – but GitHub themselves haven't yet launched it for #npm

    @openssf has even launched a #TrustedPublishers guideline: repos.openssf.org/trusted-publ

    blog.rubygems.org/2023/12/14/t

  2. Its a bit weird that #GitHub spearheaded #OIDC based authentication to retrieve short lived tokens for cloud platforms and then #PyPi, #RubyGems and even #Dart went and used that to enable short lived tokens for publishing packages – but GitHub themselves haven't yet launched it for #npm

    @openssf has even launched a #TrustedPublishers guideline: repos.openssf.org/trusted-publ

    blog.rubygems.org/2023/12/14/t

  3. Its a bit weird that #GitHub spearheaded #OIDC based authentication to retrieve short lived tokens for cloud platforms and then #PyPi, #RubyGems and even #Dart went and used that to enable short lived tokens for publishing packages – but GitHub themselves haven't yet launched it for #npm

    @openssf has even launched a #TrustedPublishers guideline: repos.openssf.org/trusted-publ

    blog.rubygems.org/2023/12/14/t

  4. Its a bit weird that #GitHub spearheaded #OIDC based authentication to retrieve short lived tokens for cloud platforms and then #PyPi, #RubyGems and even #Dart went and used that to enable short lived tokens for publishing packages – but GitHub themselves haven't yet launched it for #npm

    @openssf has even launched a #TrustedPublishers guideline: repos.openssf.org/trusted-publ

    blog.rubygems.org/2023/12/14/t

  5. Just released: #cherry_picker 2.3.0 πŸš€

    This tool creates backports for CPython when the Miss Islington bot can't, usually due to a merge conflict.

    πŸ’ Add support for #Python 3.13, drop EOL 3.8
    πŸ’ Resolve usernames when remote ends with a trailing slash
    πŸ’ Optimize validate_sha() with --max-count=1
    πŸ’ Remove multiple commit prefixes
    πŸ’ Handle whitespace when calculating usernames
    πŸ’ Publish to PyPI using #TrustedPublishers
    πŸ’ Generate #PEP740 attestations
    πŸ’ And more!

    pypi.org/project/cherry-picker

    #release

  6. Just released: #cherry_picker 2.3.0 πŸš€

    This tool creates backports for CPython when the Miss Islington bot can't, usually due to a merge conflict.

    πŸ’ Add support for #Python 3.13, drop EOL 3.8
    πŸ’ Resolve usernames when remote ends with a trailing slash
    πŸ’ Optimize validate_sha() with --max-count=1
    πŸ’ Remove multiple commit prefixes
    πŸ’ Handle whitespace when calculating usernames
    πŸ’ Publish to PyPI using #TrustedPublishers
    πŸ’ Generate #PEP740 attestations
    πŸ’ And more!

    pypi.org/project/cherry-picker

    #release

  7. Just released: #cherry_picker 2.3.0 πŸš€

    This tool creates backports for CPython when the Miss Islington bot can't, usually due to a merge conflict.

    πŸ’ Add support for #Python 3.13, drop EOL 3.8
    πŸ’ Resolve usernames when remote ends with a trailing slash
    πŸ’ Optimize validate_sha() with --max-count=1
    πŸ’ Remove multiple commit prefixes
    πŸ’ Handle whitespace when calculating usernames
    πŸ’ Publish to PyPI using #TrustedPublishers
    πŸ’ Generate #PEP740 attestations
    πŸ’ And more!

    pypi.org/project/cherry-picker

    #release

  8. Just released: #cherry_picker 2.3.0 πŸš€

    This tool creates backports for CPython when the Miss Islington bot can't, usually due to a merge conflict.

    πŸ’ Add support for #Python 3.13, drop EOL 3.8
    πŸ’ Resolve usernames when remote ends with a trailing slash
    πŸ’ Optimize validate_sha() with --max-count=1
    πŸ’ Remove multiple commit prefixes
    πŸ’ Handle whitespace when calculating usernames
    πŸ’ Publish to PyPI using #TrustedPublishers
    πŸ’ Generate #PEP740 attestations
    πŸ’ And more!

    pypi.org/project/cherry-picker

    #release

  9. πŸ₯šπŸ°πŸ›žπŸ Exciting!

    I'm doing the first @pillow release using cibuildwheel + PyPI publish GitHub Action + Trusted Publishers!

    It'll take just under three hours to build 68 wheels and an sdist, and then upload them automatically to @pypi 🀞

    The matrix covers CPython 3.8-3.12, PyPy 3.9-3.10, manylinux, musllinux, macOS Intel + Apple Silicon, Windows 32-bit + 64-bit + ARM...

    Follow along the Easter fun at github.com/python-pillow/Pillo !

    #Python #Pillow #PythonPillow #PyPI #TrustedPublishers #cibuildwheel

  10. πŸ₯šπŸ°πŸ›žπŸ Exciting!

    I'm doing the first @pillow release using cibuildwheel + PyPI publish GitHub Action + Trusted Publishers!

    It'll take just under three hours to build 68 wheels and an sdist, and then upload them automatically to @pypi 🀞

    The matrix covers CPython 3.8-3.12, PyPy 3.9-3.10, manylinux, musllinux, macOS Intel + Apple Silicon, Windows 32-bit + 64-bit + ARM...

    Follow along the Easter fun at github.com/python-pillow/Pillo !

    #Python #Pillow #PythonPillow #PyPI #TrustedPublishers #cibuildwheel

  11. πŸ₯šπŸ°πŸ›žπŸ Exciting!

    I'm doing the first @pillow release using cibuildwheel + PyPI publish GitHub Action + Trusted Publishers!

    It'll take just under three hours to build 68 wheels and an sdist, and then upload them automatically to @pypi 🀞

    The matrix covers CPython 3.8-3.12, PyPy 3.9-3.10, manylinux, musllinux, macOS Intel + Apple Silicon, Windows 32-bit + 64-bit + ARM...

    Follow along the Easter fun at github.com/python-pillow/Pillo !

    #Python #Pillow #PythonPillow #PyPI #TrustedPublishers #cibuildwheel

  12. πŸ₯šπŸ°πŸ›žπŸ Exciting!

    I'm doing the first @pillow release using cibuildwheel + PyPI publish GitHub Action + Trusted Publishers!

    It'll take just under three hours to build 68 wheels and an sdist, and then upload them automatically to @pypi 🀞

    The matrix covers CPython 3.8-3.12, PyPy 3.9-3.10, manylinux, musllinux, macOS Intel + Apple Silicon, Windows 32-bit + 64-bit + ARM...

    Follow along the Easter fun at github.com/python-pillow/Pillo !

    #Python #Pillow #PythonPillow #PyPI #TrustedPublishers #cibuildwheel

  13. Exciting news from #PyPI, just in time for @PyConUS:

    "Starting today, PyPI package maintainers can adopt a new, more secure publishing method that does not require long-lived passwords or API tokens to be shared with external systems."

    I've been part of the private beta and it works really well!

    blog.pypi.org/posts/2023-04-20

    #Python #PyConUS #TrustedPublishers

  14. Exciting news from #PyPI, just in time for @PyConUS:

    "Starting today, PyPI package maintainers can adopt a new, more secure publishing method that does not require long-lived passwords or API tokens to be shared with external systems."

    I've been part of the private beta and it works really well!

    blog.pypi.org/posts/2023-04-20

    #Python #PyConUS #TrustedPublishers

  15. Exciting news from #PyPI, just in time for @PyConUS:

    "Starting today, PyPI package maintainers can adopt a new, more secure publishing method that does not require long-lived passwords or API tokens to be shared with external systems."

    I've been part of the private beta and it works really well!

    blog.pypi.org/posts/2023-04-20

    #Python #PyConUS #TrustedPublishers

  16. Exciting news from #PyPI, just in time for @PyConUS:

    "Starting today, PyPI package maintainers can adopt a new, more secure publishing method that does not require long-lived passwords or API tokens to be shared with external systems."

    I've been part of the private beta and it works really well!

    blog.pypi.org/posts/2023-04-20

    #Python #PyConUS #TrustedPublishers