
Trusted Publishing — Eliminating Credentials from Your Release Workflow
About the event
🔒 Join us for an enlightening talk on Trusted Publishing!
In February 2024, around 10% of PyPI uploads utilized Trusted Publishers. By October 2025, that number skyrocketed to over 25%, showcasing a significant shift towards eliminating long-lived credentials. If you’re still relying on stored API tokens, this session will guide you on modernizing your approach.
✨ What to Expect:
- Learn how Trusted Publishing employs OpenID Connect (OIDC) to generate short-lived, automatically-scoped tokens from CI/CD environments, eliminating the need for passwords and API tokens.
- A comprehensive walkthrough of setting up Trusted Publishers for GitHub Actions (and more!)
- Understand the accessible security model and explore case studies, including the Sigstore integration used in the forensic investigation of the 2024 Ultralytics compromise.
🎓 What You'll Gain:
- Step-by-step setup process and troubleshooting tips.
- Migration strategies for maintainers with multiple packages.
- Insights into the critical need for token removal when Trusted Publishing is in place, as well as when restricted API tokens are appropriate fallback options.
Whether you maintain one package or a hundred, you’ll leave this session with the tools needed for credential-free publishing! 🔑
📍 Location: 12 W 39th St
🌐 Register Here!
Location
12 W 39th St
Get directions








