Trusted Publishing is a recommended security capability by the OpenSSF Securing Software Repositories Working Group
as it removes the need to securely manage an API token in the build system.
This timeline lists which package registries support it and when it was added.
Automated publishing of packages to pub.dev
pub.dev adds support for automated publishing which supports publishing from the following sources: GitHub Actions, Google Cloud Build, anywhere else using a GCP service account.
PyPI expands Trusted Publisher Support to GitLab Self-Managed and enables Pending Trusted Publishers for Organizations
Support for GitLab Self-Managed instances is now in beta, and it is now possible to pending Trusted Publisher at the
Organization level which was previously only possible at the user level.