diff --git a/.github/workflows/python-publish.yml b/.github/workflows/python-publish.yml index e2cbcd7..9df67bb 100644 --- a/.github/workflows/python-publish.yml +++ b/.github/workflows/python-publish.yml @@ -21,6 +21,9 @@ jobs: runs-on: ubuntu-latest environment: release + permissions: + # This permission is mandatory for trusted publishing + id-token: write steps: - uses: actions/checkout@v3 @@ -35,7 +38,4 @@ jobs: - name: Build package run: python -m build - name: Publish package - uses: pypa/gh-action-pypi-publish@27b31702a0e7fc50959f5ad993c78deac1bdfc29 - with: - user: __token__ - password: ${{ secrets.PYPI_API_TOKEN }} + uses: pypa/gh-action-pypi-publish@release/v1