OK, I said it:
> As an aside, I think we should seriously be considering moving off of GitHub, not committing ourselves more. The hosting is fine. The free CI is fine. Everything else is increasing problematic.
https://forum.djangoproject.com/t/adopt-pep-740-digital-attestations-for-django-releases/42460/7
Adopt PEP 740 digital attestations for Django releases
It seems a bit previous to open a ticket. That will only be closed pending a discussion here. Q: is there a list of PyPI Trusted Publishers available anywhere? As far as I can see, is it only GitHub? It’s not clear to me that it’s actually possible to become a Trusted Publisher unless you’re a public CI host of some renown. It looks like these PyPI advances are tied to GitHub, which is a shame if so. I would sceptical about moving the release process to GitHub Actions. I understand the conveni...