Skip to content

CI: improve security, add zizmor and trusted publishing - #875

Merged
rgommers merged 4 commits into
PyWavelets:mainfrom
rgommers:ci-improvements
Sep 9, 2026
Merged

CI: improve security, add zizmor and trusted publishing#875
rgommers merged 4 commits into
PyWavelets:mainfrom
rgommers:ci-improvements

Conversation

@rgommers

@rgommers rgommers commented Sep 8, 2026

Copy link
Copy Markdown
Member

This should address the backlog of maintenance on publishing releases and other security-related topics. Content largely taken over from how it's done in NumPy.

I used Codex Sol 5.6 for an audit, and it implemented the changes in the last commit based on a local zizmor run.

@rgommers rgommers added this to the v1.11.0 milestone Sep 8, 2026
@rgommers rgommers added Official binaries CI Continuous integration labels Sep 8, 2026
@rgommers

rgommers commented Sep 8, 2026

Copy link
Copy Markdown
Member Author

@grlee77 it looks like you're the only owner of PyWavelets on TestPyPI - could you please add me (user rgommers)?

@rgommers

rgommers commented Sep 8, 2026

Copy link
Copy Markdown
Member Author

Changes to make once this PR is merged:

  • Change GITHUB_TOKEN to read-only by default
  • Remove release secrets from this repo
  • Enable trusted publishing on PyPI

@rgommers
rgommers merged commit 65f19a7 into PyWavelets:main Sep 9, 2026
20 checks passed
@rgommers
rgommers deleted the ci-improvements branch September 9, 2026 20:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CI Continuous integration Official binaries

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant