I just came across a [project named `zizmor`](http://docs.zizmor.sh/). The latest [pypa/gh-action-pypi-publish release (v1.13.0)](https://github.com/pypa/gh-action-pypi-publish/releases/tag/v1.13.0) recommends it, and I'm inclined to consider it in this project.