@brettcannon Amazing, thank you! Indeed thank you to all the PyPA folks who implemented trusted publishing, thanks to whom napari automagically ticked box 2 after ticking box 1: https://pypi.org/project/napari/0.7.0/#napari-0.7.0-py3-none-any.whl and thank you very much for the blog post which made it easy for go check that! We still use requirements.txt files for our CI constraints, though, so we'll look into migrating to pylock.toml!