diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 4eee218..323ffae 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -304,6 +304,8 @@ jobs: ] runs-on: ubuntu-latest environment: production_pypi + permissions: + id-token: write # Required for "trusted publishing" steps: - uses: actions/download-artifact@v3 @@ -326,7 +328,3 @@ jobs: - name: Publish package to PyPI uses: pypa/gh-action-pypi-publish@v1.8.10 - with: - # TODO: Change to use "Trusted publishing"? - user: __token__ - password: ${{ secrets.pypi_password }}