Skip to content

Configure PyPI trusted publishing before the first release #10

Description

@woksin

User need

Chronicle.Python releases need tokenless, maintainer-approved publication without storing a long-lived PyPI API token in GitHub.

Desired behavior

Configure the pending or existing PyPI project cratis-chronicle to trust this repository's .github/workflows/publish.yml workflow and pypi environment.

Acceptance evidence

  • The PyPI project or pending publisher names owner Cratis, repository Chronicle.Python, workflow publish.yml, and environment pypi.
  • The GitHub pypi environment retains the accepted maintainer as a required reviewer.
  • The workflow has job-scoped id-token: write and no PyPI username, password, or API token.
  • A first release is attempted only after the client has a releaseable, tested milestone.
  • The resulting package metadata, wheel, source distribution, and provenance are checked after publication.

Non-goals

  • Publishing the current empty scaffold.
  • Creating a support, compatibility, parity, or maturity commitment.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

blockedWaiting on a named dependency or gatekind/featureNew client capabilityneeds-adminRequires repository or service administrator action

Type

No type

Projects

No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions