Use trusted publishing token (#862)

This commit is contained in:
Jesse Hills 2024-04-17 10:26:39 +12:00 committed by GitHub
parent 725e501815
commit 0ad9dd5aa5
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194

View File

@ -58,11 +58,11 @@ jobs:
id-token: write
if: github.event_name == 'release' && github.event.action == 'published'
steps:
- uses: actions/download-artifact@v3
- name: Download artifacts
uses: actions/download-artifact@v3
with:
name: artifact
path: dist
- uses: pypa/gh-action-pypi-publish@release/v1
with:
password: ${{ secrets.PYPI_TOKEN }}
- name: Publish to PyPI
uses: pypa/gh-action-pypi-publish@v1.8.14