GeistHaus
log in · sign up

Introducing 'Trusted Publishers' - The Python Package Index Blog

blog.pypi.org

Announcing a new, more secure way to publish to PyPI

7 pages link to this URL
Why Use Trusted Publishing for PyPI?

Trusted publishing replaces long-lived PyPI API tokens with short-lived OIDC credentials, eliminating the most common way attackers gain unauthorized upload access to PyPI.

0 inbound links article en handbook
How to npm and avoid getting rekt

As a consequence of the Shai-Hulud worm that struck the NPM ecosystem, we were motivated to create this article, shedding some light on best practices.

1 inbound link article en npmsecurity-awarenesspublishingpnpmyarnhardening
Trusted publishing: a new benchmark for packaging security

Read the official announcement on the PyPI blog as well! For the past year, we’ve worked with the Python Package Index to add a new, more secure authentication method called “trusted publishing.” Trusted publishing eliminates the need for long-lived API tokens and passwords, reducing the risk of supply chain attacks and credential leaks while also […]

3 inbound links article en ecosystem-securityengineering-practice ecosystem-securityengineering-practice
Our plan for a more secure npm supply chain

GitHub is strengthening npm's security with stricter authentication, granular tokens, and enhanced trusted publishing.

12 inbound links article en SecuritySupply chain security GitHub Security Labnpmsupply chain security