Hacker News new | ask | show | jobs
by di 1039 days ago
This is why PyPI recommends using Trusted Publishing (https://docs.pypi.org/trusted-publishers/) which removes the need for long-lived tokens entirely.