Skip to content

CI: improve security, add zizmor and trusted publishing - #875

Open
rgommers wants to merge 4 commits into
PyWavelets:mainfrom
rgommers:ci-improvements
Open

CI: improve security, add zizmor and trusted publishing#875
rgommers wants to merge 4 commits into
PyWavelets:mainfrom
rgommers:ci-improvements

Conversation

@rgommers

@rgommers rgommers commented Sep 8, 2026

Copy link
Copy Markdown
Member

This should address the backlog of maintenance on publishing releases and other security-related topics. Content largely taken over from how it's done in NumPy.

I used Codex Sol 5.6 for an audit, and it implemented the changes in the last commit based on a local zizmor run.

@rgommers rgommers added this to the v1.11.0 milestone Sep 8, 2026
@rgommers rgommers added Official binaries CI Continuous integration labels Sep 8, 2026
@rgommers

rgommers commented Sep 8, 2026

Copy link
Copy Markdown
Member Author

@grlee77 it looks like you're the only owner of PyWavelets on TestPyPI - could you please add me (user rgommers)?

@rgommers

rgommers commented Sep 8, 2026

Copy link
Copy Markdown
Member Author

Changes to make once this PR is merged:

  • Change GITHUB_TOKEN to read-only by default
  • Remove release secrets from this repo
  • Enable trusted publishing on PyPI

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CI Continuous integration Official binaries

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant