User need
Chronicle.Python releases need tokenless, maintainer-approved publication without storing a long-lived PyPI API token in GitHub.
Desired behavior
Configure the pending or existing PyPI project cratis-chronicle to trust this repository's .github/workflows/publish.yml workflow and pypi environment.
Acceptance evidence
- The PyPI project or pending publisher names owner
Cratis, repository Chronicle.Python, workflow publish.yml, and environment pypi.
- The GitHub
pypi environment retains the accepted maintainer as a required reviewer.
- The workflow has job-scoped
id-token: write and no PyPI username, password, or API token.
- A first release is attempted only after the client has a releaseable, tested milestone.
- The resulting package metadata, wheel, source distribution, and provenance are checked after publication.
Non-goals
- Publishing the current empty scaffold.
- Creating a support, compatibility, parity, or maturity commitment.
User need
Chronicle.Python releases need tokenless, maintainer-approved publication without storing a long-lived PyPI API token in GitHub.
Desired behavior
Configure the pending or existing PyPI project
cratis-chronicleto trust this repository's.github/workflows/publish.ymlworkflow andpypienvironment.Acceptance evidence
Cratis, repositoryChronicle.Python, workflowpublish.yml, and environmentpypi.pypienvironment retains the accepted maintainer as a required reviewer.id-token: writeand no PyPI username, password, or API token.Non-goals