So I can use the "Trusted Publisher" feature to publish from github without secrets, but no obvious clue on #pypi to say that the package was uploaded via Trusted Publisher.
https://github.com/matthewdeanmartin/markpickle/blob/main/.github/workflows/build.yml#L36