|
|
|
|
|
by veeti
164 days ago
|
|
Yet in practice, only the big boys are allowed to become "Trusted Publishers": > In the interest of making the best use of PyPI's finite resources, we only plan to support platforms that have a reasonable level of usage among PyPI users for publishing. Additionally, we have high standards for overall reliability and security in the operation of a supported Identity Provider: in practice, this means that a home-grown or personal use IdP will not be eligible. How long until everyone is forced to launder their artifacts using Microsoft (TM) GitHub (R) to be "trusted"? [1] https://docs.pypi.org/trusted-publishers/internals/#how-do-i... |
|