From f47ba5460b30a07e5c6264e8a3e1100f65a8e33a Mon Sep 17 00:00:00 2001 From: Sergio Souza Costa Date: Fri, 27 Feb 2026 14:11:06 -0300 Subject: [PATCH 1/2] ci: fixing python-publish to use token --- .github/workflows/python-publish.yml | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/.github/workflows/python-publish.yml b/.github/workflows/python-publish.yml index eabe004..8ad7402 100644 --- a/.github/workflows/python-publish.yml +++ b/.github/workflows/python-publish.yml @@ -3,7 +3,7 @@ name: Publish to PyPI on: release: types: [published] - workflow_dispatch: # para testar sem criar Release + workflow_dispatch: permissions: contents: read @@ -48,5 +48,4 @@ jobs: uses: pypa/gh-action-pypi-publish@release/v1 with: password: ${{ secrets.PYPI_API_TOKEN }} - packages-dir: dist/ - + packages-dir: dist/ \ No newline at end of file From 602d922cc5e2571ae85b3496b5747220d06d6a07 Mon Sep 17 00:00:00 2001 From: Sergio Souza Costa Date: Fri, 27 Feb 2026 14:23:39 -0300 Subject: [PATCH 2/2] ci: add id-token write permission to publish job --- .github/workflows/python-publish.yml | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/.github/workflows/python-publish.yml b/.github/workflows/python-publish.yml index 8ad7402..0767949 100644 --- a/.github/workflows/python-publish.yml +++ b/.github/workflows/python-publish.yml @@ -36,7 +36,9 @@ jobs: publish: runs-on: ubuntu-latest needs: build - + permissions: + id-token: write + steps: - name: Download artifact uses: actions/download-artifact@v4