-
Notifications
You must be signed in to change notification settings - Fork 1.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
ENH: Ensure PyPI marks URLs as "verified" #2892
Comments
Hm. The version badge does directly link to https://pypi.org/project/pypdf/ |
Let's see if somebody else has an idea: pypi/warehouse#16836 |
I do not get the same results from the linked docs as you: If one of the listed URLs points to PyPI, they are automatically verified. For GitHub URLs, we would have to switch from the current token-based approach to trusted publishing. This matches the conclusions from the linked issue as well. |
I've now
I haven't done this before. I guess we will see with the next release if it was done correctly :-) |
AFAIK this is not sufficient, as we still use a token-based PyPI upload. |
The changes where not sufficient as the latest release still does not show the values as verified. To fix this, we would have to migrate the |
Currently, pypdf on pypi looks like this:
I would like the project URLs to be marked by PyPI as "verified"
https://docs.pypi.org/project_metadata/ indicates that just a backlink is necessary. We have that, but just indirectly via https://badge.fury.io/py/pypdf. Instead, we should link directly to PyPI
The text was updated successfully, but these errors were encountered: