|
|
|
|
|
by mulmboy
197 days ago
|
|
It does largely avoid the issue if you configure to allow only specific environments AND you require reviews before pushing/merging to branches in that environment. https://docs.pypi.org/trusted-publishers/adding-a-publisher/ For a malicious version to be published would then require full merge which is a fairly high bar. AWS allows similar |
|