fix(python/pypi): add note about protected variables
The advice to set protection on for PyPI API tokens is generally good but it also requires that the appropriate protection rules have been added for tagged commits. Note that this may not always be the case.