-
Notifications
You must be signed in to change notification settings - Fork 302
Open
Labels
infrastructureShared CMake, github, etc infrastructureShared CMake, github, etc infrastructure
Description
I noticed that every time we publish a package, I receive an email from PyPI:
[PyPI] Trusted Publisher for project cuda-cccl can be made more secure
A Trusted Publisher for project [cuda-cccl](https://pypi.org/project/cuda-cccl/) was just used from a CI/CD job configured with a GitHub environment. The environment used was: pypi.
Since the Trusted Publisher is configured to allow any environment, for security reasons we recommend constraining it to only one.
If you are an owner of this project, you can automatically constrain this Trusted Publisher to 'pypi' by following this link: constrain publisher (link removed).
Alternatively, you can do this manually by going to the project's publishing settings (link removed), deleting the existing Trusted Publisher and creating a new one with the environment set to 'pypi'.
If you have questions, you can email [admin@pypi.org](mailto:admin@pypi.org) to communicate with the PyPI administrators.
This can be easily followed and set up. But I can't access the admin panel in this repo to confirm if the pypi environment already exists (seems to be the case).
Metadata
Metadata
Assignees
Labels
infrastructureShared CMake, github, etc infrastructureShared CMake, github, etc infrastructure
Type
Projects
Status
Todo