-
Notifications
You must be signed in to change notification settings - Fork 0
Open
Labels
governanceProject governance and repo configurationProject governance and repo configuration
Description
Pre-1.0 security item (ADR-0021)
Use OIDC trusted publishing instead of long-lived API tokens for package publishing.
When to action
When crates.io and PyPI accounts/organizations are created for aces-framework.
What to do
- Configure GitHub OIDC identity provider with crates.io and PyPI
- Update CI release workflows to use
pypi-publishandcargo-publishwith OIDC - Remove any long-lived API tokens from GitHub secrets
References
- STANDARDS.md §10.3, §10.7
- ADR-0021 Layer 3 (CI/CD Security)
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
governanceProject governance and repo configurationProject governance and repo configuration