Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Switch to trusted publishing for package upload to PyPI in CI #1110

Open
Assignees
avdivan
@EpicWink

Description

@EpicWink

Trusted publishing (with attestations) means I can know for certain that what I download from PyPI is the same artefact which was generated in GitHub CI, meaning that what I see in GitHub is the same as what is installed - handy for auditing (rather than having to manually review all of the installed files on each release).

Seethe Python packaging documentation,the PyPI documentation, andthe official pypi-publish GitHub action documentation on trusted publishing - you'll need to configure an environment in PyPI and GitHub. You will be able to remove theOPENCV_CONTRIB_PYTHON_PASSWORD project secret.

Should be as simple as switching to thepypa/gh-action-pypi-publish action (instead oftwine upload ..., settingskip-existing: true) in the "Upload wheels" steps of theRelease jobs of all the workflows, and adding environment and permissions to those jobs.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions


    [8]ページ先頭

    ©2009-2025 Movatter.jp