Maintainer setup¶
The repository workflows are secure by default where settings can be expressed as code. Complete the following account-level settings in GitHub and PyPI.
GitHub¶
- Enable dependency-graph, Dependabot alerts, and Dependabot security updates.
- Protect
mainand require thequalityand Python 3.10–3.14toxchecks. - Create a
pypideployment environment, restrict it tomain, and require a reviewer for package publication. - Enable private vulnerability reporting for the process documented in
SECURITY.md.
PyPI trusted publishing¶
Configure a trusted publisher for:
- owner:
peter-daly - repository:
benchbro - workflow:
release.yml - environment:
pypi
Then set the GitHub Actions repository variable PYPI_TRUSTED_PUBLISHING=true
and remove the PYPI_TOKEN secret. Until that variable is enabled, the release
workflow retains the existing token path so maintenance changes do not interrupt
publishing. Releases are manual: bump the project version, merge a green build to
main, then dispatch the Release workflow.