From 02f1c091d4ecae1820021bdf5a1c51b11ba8502c Mon Sep 17 00:00:00 2001 From: Yanjun Qi / Jane Date: Fri, 14 Aug 2026 12:27:50 -0400 Subject: [PATCH] CI: switch PyPI publish to Trusted Publishing (OIDC) The username/password (secrets.PYPI_USERNAME/PYPI_PASSWORD) upload in the v0.3.11 release attempt failed with "403 Forbidden" from PyPI - password-based twine uploads are no longer accepted now that PyPI requires token/OIDC-based auth for uploads. Switch to the official pypa/gh-action-pypi-publish action with OIDC Trusted Publishing, which needs no stored secrets at all: PyPI verifies the workflow's identity directly via GitHub's OIDC token. Requires a one-time, PyPI-side config: add this repo/workflow as a Trusted Publisher on the `textattack` PyPI project (PyPI account -> Manage project -> Publishing -> Add a new publisher), owner "QData", repo "TextAttack", workflow "publish-to-pypi.yml", environment left blank (this workflow doesn't use one). The old PYPI_USERNAME/PYPI_PASSWORD secrets are no longer read by this workflow and can be removed once trusted publishing is confirmed working. Co-Authored-By: Claude Sonnet 5 --- .github/workflows/publish-to-pypi.yml | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/.github/workflows/publish-to-pypi.yml b/.github/workflows/publish-to-pypi.yml index 3738cd84..cc0c1e68 100644 --- a/.github/workflows/publish-to-pypi.yml +++ b/.github/workflows/publish-to-pypi.yml @@ -7,6 +7,8 @@ on: jobs: deploy: runs-on: ubuntu-latest + permissions: + id-token: write # required for PyPI Trusted Publishing (OIDC) steps: - uses: actions/checkout@v4 @@ -16,11 +18,9 @@ jobs: python-version: "3.11" - name: Install dependencies run: | - python -m pip install --upgrade pip setuptools wheel twine - - name: Build and publish - env: - TWINE_USERNAME: ${{ secrets.PYPI_USERNAME }} - TWINE_PASSWORD: ${{ secrets.PYPI_PASSWORD }} + python -m pip install --upgrade pip setuptools wheel + - name: Build package run: | python setup.py sdist bdist_wheel - twine upload dist/* + - name: Publish to PyPI + uses: pypa/gh-action-pypi-publish@release/v1