diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index a651c06..cd002e9 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -167,6 +167,8 @@ jobs: upload_pypi: needs: [build_wheels, build_sdist] runs-on: ubuntu-latest + permissions: + id-token: write # needed for trusted publishing if: github.event_name == 'push' && startsWith(github.ref, 'refs/tags/') steps: - uses: actions/download-artifact@v4 @@ -174,9 +176,7 @@ jobs: pattern: artifact-* merge-multiple: true path: dist - - uses: pypa/gh-action-pypi-publish@v1.5.0 - with: - password: ${{ secrets.PYPI_API_TOKEN }} - # testing: + - uses: pypa/gh-action-pypi-publish@release/v1 + # testing: + #with: #repository_url: https://test.pypi.org/legacy/ - #password: ${{ secrets.TEST_PYPI_API_TOKEN }}