Skip to content

SEC: avoid leaking credentials in GHA#2769

Merged
agriyakhetarpal merged 1 commit intopypa:mainfrom
neutrinoceros:sec/cred-leak
Mar 11, 2026
Merged

SEC: avoid leaking credentials in GHA#2769
agriyakhetarpal merged 1 commit intopypa:mainfrom
neutrinoceros:sec/cred-leak

Conversation

@neutrinoceros
Copy link
Contributor

based off #2762 to avoid merge conflicts later

Copy link
Member

@agriyakhetarpal agriyakhetarpal left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @neutrinoceros! I think we should get this in by limiting it to setting persist-credentials: false, so that the SHA-pinning discussion will take place in #2744. I assume that will be fairly agreed upon as a smaller change.

@neutrinoceros neutrinoceros marked this pull request as ready for review March 11, 2026 12:08
@neutrinoceros
Copy link
Contributor Author

done

@agriyakhetarpal agriyakhetarpal merged commit eaf116e into pypa:main Mar 11, 2026
38 checks passed
@neutrinoceros neutrinoceros deleted the sec/cred-leak branch March 11, 2026 14:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants