
Trusted Publishing — Eliminating Credentials from Your Release Workflow
In February 2024, about 10% of PyPI uploads used Trusted Publishers. By October 2025, that number exceeded 25%, a massive shift toward eliminating long-lived credentials. For maintainers still using stored API tokens, this talk demonstrates why and how to modernize.
Trusted Publishing uses OpenID Connect (OIDC) to generate short-lived, automatically-scoped tokens from CI/CD environments. No passwords. No API tokens to rotate. No secrets stored in repositories.
This talk walks through setting up Trusted Publishers for GitHub Actions (as an example, but others are available), explains the security model in accessible terms, and shares case studies, including how Sigstore integration enabled forensic investigation of the 2024 Ultralytics compromise.
Attendees will learn the step-by-step setup process, common pitfalls and troubleshooting, and migration strategies for maintainers with many packages. The session also covers why token removal is critical when Trusted Publishing in place, and when restricted API tokens remain the appropriate fallback. Whether maintaining one package or a hundred, attendees will leave with everything needed to adopt credential-free publishing.
12 W 39th St
Get directions








