From 93a7eebeed77b78deb0431cf6de4a4cd3faf0538 Mon Sep 17 00:00:00 2001 From: jw9829 <245427686+jw9829@users.noreply.github.com> Date: Sun, 27 Sep 2026 14:22:45 -0400 Subject: [PATCH 1/2] Recommend Trusted Publishing in tutorial --- source/tutorials/packaging-projects.rst | 12 ++++++++---- 1 file changed, 8 insertions(+), 4 deletions(-) diff --git a/source/tutorials/packaging-projects.rst b/source/tutorials/packaging-projects.rst index 4f69de20be..0233ea0eea 100644 --- a/source/tutorials/packaging-projects.rst +++ b/source/tutorials/packaging-projects.rst @@ -495,15 +495,19 @@ When you are ready to upload a real package to the Python Package Index you can do much the same as you did in this tutorial, but with these important differences: +For projects published through a supported CI/CD platform, we recommend +:ref:`Trusted Publishing ` instead of storing a long-lived +API token. The linked guide shows how to set this up with GitHub Actions. + * Choose a memorable and unique name for your package. You don't have to append your username as you did in the tutorial, but you can't use an existing name. * Register an account on https://pypi.org - note that these are two separate servers and the login details from the test server are not shared with the main server. -* Use ``twine upload dist/*`` to upload your package and enter your credentials - for the account you registered on the real PyPI. Now that you're uploading - the package in production, you don't need to specify ``--repository``; the - package will upload to https://pypi.org/ by default. +* For a manual upload, use ``twine upload dist/*`` to upload your package and + enter your credentials for the account you registered on the real PyPI. Now + that you're uploading the package in production, you don't need to specify + ``--repository``; the package will upload to https://pypi.org/ by default. * Install your package from the real PyPI using ``python3 -m pip install [your-package]``. At this point if you want to read more on packaging Python libraries here are From 6017b2f4692ea26f97d33f9a34108cdf35d42fb6 Mon Sep 17 00:00:00 2001 From: jw9829 <245427686+jw9829@users.noreply.github.com> Date: Sun, 27 Sep 2026 20:22:36 -0400 Subject: [PATCH 2/2] Move Trusted Publishing note into a tip --- source/tutorials/packaging-projects.rst | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/source/tutorials/packaging-projects.rst b/source/tutorials/packaging-projects.rst index 0233ea0eea..8f91796ec5 100644 --- a/source/tutorials/packaging-projects.rst +++ b/source/tutorials/packaging-projects.rst @@ -495,10 +495,6 @@ When you are ready to upload a real package to the Python Package Index you can do much the same as you did in this tutorial, but with these important differences: -For projects published through a supported CI/CD platform, we recommend -:ref:`Trusted Publishing ` instead of storing a long-lived -API token. The linked guide shows how to set this up with GitHub Actions. - * Choose a memorable and unique name for your package. You don't have to append your username as you did in the tutorial, but you can't use an existing name. * Register an account on https://pypi.org - note that these are two separate @@ -510,6 +506,12 @@ API token. The linked guide shows how to set this up with GitHub Actions. ``--repository``; the package will upload to https://pypi.org/ by default. * Install your package from the real PyPI using ``python3 -m pip install [your-package]``. +.. tip:: + + For projects published through a supported CI/CD platform, we recommend + :ref:`Trusted Publishing ` instead of storing a long-lived + API token. The linked guide shows how to set this up with GitHub Actions. + At this point if you want to read more on packaging Python libraries here are some things you can do: