|
|
|
|
|
by woodruffw
165 days ago
|
|
> If that is correct, I thought this was discussed when Trusted Publishing was proposed for Rust that it was not meant to replace local publishing, only harden CI publishing. Yes, that's right, and that's how it was implemented for both Rust and Python. NPM seems to have decided to do their own thing here. (More precisely, I think NPM still allows local publishing with an API token, they just won't grant long-lived ones anymore.) |
|
It was a good intention, but the ramifications of it I don't think are great.