Sometimes you need to set environment variables with secrets, API keys or tokens, but they can be susceptible to exfiltration by malware, as seen during the recent Shai-Hulud attack. For publishing to PyPI, it’s strongly recommended to use Trusted Publishing rather than managing long-lived tokens on…
No articles.