mirror of
https://github.com/pypa/gh-action-pypi-publish.git
synced 2024-12-27 09:32:15 -05:00
📝Fix a typo in "privileges" @ README
This commit is contained in:
parent
7252a9a09c
commit
cbd6d01d85
1 changed files with 1 additions and 1 deletions
|
@ -212,7 +212,7 @@ Invoking `pypi-publish` from composite actions is unsupported. It is not
|
||||||
tested. GitHub Runners have limitations and bugs in this case. But more
|
tested. GitHub Runners have limitations and bugs in this case. But more
|
||||||
importantly, this is usually an indication of using it insecurely. When
|
importantly, this is usually an indication of using it insecurely. When
|
||||||
using [Trusted Publishing][trusted publisher], it is imperative to keep
|
using [Trusted Publishing][trusted publisher], it is imperative to keep
|
||||||
build machinery invocation in a separate job with restrictive priviliges
|
build machinery invocation in a separate job with restrictive privileges
|
||||||
as [Trusted Publishing][trusted publisher] itself requires elevated
|
as [Trusted Publishing][trusted publisher] itself requires elevated
|
||||||
permissions to make use of OIDC. Our observation is that the users
|
permissions to make use of OIDC. Our observation is that the users
|
||||||
sometimes create in-project composite actions that invoke building and
|
sometimes create in-project composite actions that invoke building and
|
||||||
|
|
Loading…
Reference in a new issue