Should you trust Trusted Publishing? - Nikita Karamov @EuroPythonConference
Should you trust Trusted Publishing? - Nikita Karamov  @EuroPythonConference
Uploaded August 2026 | Updated September 2026, 2 weeks ago
[EuroPython 2026 - S3B on 2026-07-15]
🎀 *Should you trust Trusted Publishing? by Nikita Karamov*
πŸ”— https://ep2026.europython.eu/session/should-you-trust-trusted-publishing

πŸ“ Abstract:
In 2023, PyPI started supporting Trusted Publishers: A way to publish Python packages to PyPI without relying on insecure password and short-lived tokens. Three years later, this approach has become the default answer to package registries' security, as it found its way into NPM, crates.io, and RubyGems. But does it actually offer the benefits we hoped it would? Can you really trust the green checkmark, and if you can't, what's the point?

In this talk, I want to look closely at what Trusted Publishers are, and what we _might_ think they are; who they do and do not protect. We'll explore the potential centralization problem of relying on Big Tech, US-based CI providers, leaving little room for smaller players like Codeberg and Sourcehut, as well as self-hosted Git forges and CI engines.

But even when using GitHub, Trusted Publisher may be tricky to get right, exposing different backdoors for the attacker to exploit. I want to discuss the illusion of security Trusted Publishers may give the inexperienced PyPI user; that is, if they actually decide to look at the hidden details of the published artifacts. How can we safeguard our Python projects, and should it be us who safeguards it? I will propose some solutions to this issue, including how the package managers and the PyPI registry itself can help us in this task.

Lastly, we'll reminisce about the past in search of answer. Maybe OpenPGP β€˜Web of Trust’ wasn't such a bad idea after all? Can we regain our independence in deciding who we do and don't trust?

---
This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License: creativecommons.org/licenses/by-nc-sa/4.0
Should you trust Trusted Publishing? - Nikita KaramovHold on! You have a data team in PyCon Taiwan! β€” Wei LeeHow Many EuroPythons Attended β€” Lara KramerFavorite Thing About EuroPython β€” Cheuk Ting HoHow to Maintain 60 Integrations and Not Go Bananas - Ivana KellyerWhat’s Paolo looking forward to at the next #EuroPython? 🀩Design Pressure: The Invisible Hand That Shapes Your Code - Hynek SchlawackGPU Programming in Pure Python - Bryce Adelstein LelbachEP2026 - Ask Me Anything About CfP Workshop🐍 Attended 6 EuroPython and countingFavorite Command Line Utility β€” Jurgen GmachOffline Disaster Relief Coordination with OpenStreetMap and FastAPI β€” Jannis LΓΌbbe
EuroPython Conference |

Should you trust Trusted Publishing? - Nikita Karamov

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER