Skip to content

Merge pull request #126 from washingtonpost/release/2.2.0 #31

Merge pull request #126 from washingtonpost/release/2.2.0

Merge pull request #126 from washingtonpost/release/2.2.0 #31

Triggered via push November 1, 2024 20:58
Status Failure
Total duration 42s
Artifacts

release.yml

on: push
Build Python distribution and publish to TestPyPi and PyPi
34s
Build Python distribution and publish to TestPyPi and PyPi
Fit to window
Zoom out
Zoom in

Annotations

1 error and 6 warnings
Password-based uploads disabled
As of 2024, PyPI requires all users to enable Two-Factor Authentication. This consequently requires all users to switch to either Trusted Publishers (preferred) or API tokens for package uploads. Read more: https://blog.pypi.org/posts/2023-05-25-securing-pypi-with-2fa/
Build Python distribution and publish to TestPyPi and PyPi
The following actions uses node12 which is deprecated and will be forced to run on node16: actions/setup-python@v2. For more info: https://github.blog/changelog/2023-06-13-github-actions-all-actions-will-run-on-node16-instead-of-node12-by-default/
Build Python distribution and publish to TestPyPi and PyPi
The following actions use a deprecated Node.js version and will be forced to run on node20: actions/setup-python@v2. For more info: https://github.blog/changelog/2024-03-07-github-actions-all-actions-will-run-on-node20-instead-of-node16-by-default/
Build Python distribution and publish to TestPyPi and PyPi
Input 'repository_url' has been deprecated with message: The inputs have been normalized to use kebab-case. Use `repository-url` instead.
attestations input ignored
The workflow was run with the 'attestations: true' input, but an explicit password was also set, disabling Trusted Publishing. As a result, the attestations input is ignored.
Upgrade to Trusted Publishing
Trusted Publishers allows publishing packages to PyPI from automated environments like GitHub Actions without needing to use username/password combinations or API tokens to authenticate with PyPI. Read more: https://docs.pypi.org/trusted-publishers
Create a Trusted Publisher
A new Trusted Publisher for the currently running publishing workflow can be created by accessing the following link(s) while logged-in as an owner of the package(s):