Skip to content

CI: cuda-cccl should be published with the environment name set #6907

@leofang

Description

@leofang

I noticed that every time we publish a package, I receive an email from PyPI:

[PyPI] Trusted Publisher for project cuda-cccl can be made more secure

A Trusted Publisher for project [cuda-cccl](https://pypi.org/project/cuda-cccl/) was just used from a CI/CD job configured with a GitHub environment. The environment used was: pypi.

Since the Trusted Publisher is configured to allow any environment, for security reasons we recommend constraining it to only one.

If you are an owner of this project, you can automatically constrain this Trusted Publisher to 'pypi' by following this link: constrain publisher (link removed).

Alternatively, you can do this manually by going to the project's publishing settings (link removed), deleting the existing Trusted Publisher and creating a new one with the environment set to 'pypi'.

If you have questions, you can email [admin@pypi.org](mailto:admin@pypi.org) to communicate with the PyPI administrators.

This can be easily followed and set up. But I can't access the admin panel in this repo to confirm if the pypi environment already exists (seems to be the case).

Metadata

Metadata

Assignees

No one assigned

    Labels

    infrastructureShared CMake, github, etc infrastructure

    Type

    No type

    Projects

    Status

    Todo

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions