We are currently publishing to PyPI via an API token: https://github.com/SUSE/osc-tiny/blob/f47ee8994fd65ab547b593162d58abfc72472ffb/.github/workflows/publish.yml, this is not recommended anymore as a stolen token could pwn the whole project. We could use trusted publishing instead: https://docs.pypi.org/trusted-publishers/
We are currently publishing to PyPI via an API token: https://github.com/SUSE/osc-tiny/blob/f47ee8994fd65ab547b593162d58abfc72472ffb/.github/workflows/publish.yml, this is not recommended anymore as a stolen token could pwn the whole project. We could use trusted publishing instead: https://docs.pypi.org/trusted-publishers/