| I get that, that's why I didn't go "This is Embrace Extend Extinguish", but as constructive feedback I would recommend softening the language and to replace: > STOP! You probably don't need this section; In https://docs.pypi.org/attestations/producing-attestations/#t... Perhaps also add a few of the providers you listed as well? > The only reason it emphasizes GitHub Actions is because that's where the overwhelming majority of automatic publishing traffic comes from GitHub being popular is a self-reinforcing process, if GitHub is your first class citizen for something as crucial as trusted publishing then projects on GitHub will see a higher adoption and become the de-facto "secure choice". |
If I don't want to use GitHub, let alone GitHub Actions, I am now effectively excluded from publishing my work on PyPI: quite unacceptable.