Skip to content

ci: use trusted PyPI publishing - #2

Merged
aadithyanr merged 1 commit into
mainfrom
ci/trusted-pypi-publishing
Sep 1, 2026
Merged

ci: use trusted PyPI publishing#2
aadithyanr merged 1 commit into
mainfrom
ci/trusted-pypi-publishing

Conversation

@aadithyanr

Copy link
Copy Markdown
Collaborator

Summary

  • publish releases through PyPI Trusted Publishing instead of a stored API token
  • scope the release job to read-only contents plus GitHub OIDC
  • pin the PyPI publish action to an immutable commit
  • document the keyless release flow

Validation

  • git diff --check
  • release workflow follows the official deepset standalone-component template build path
  • publisher action pinned to the current release/v1 commit

@aadithyanr
aadithyanr merged commit cd21b97 into main Sep 1, 2026
2 checks passed
@aadithyanr
aadithyanr deleted the ci/trusted-pypi-publishing branch September 1, 2026 13:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant