Skip to content

Sorry for the breakage! #26

@woodruffw

Description

@woodruffw

Hi there! Your recent failed publish to PyPI (here) set off an alert on PyPI's side, which I've been triaging.

I've isolated the problem down to an overly conservative assumption in how PyPI verifies uploaded attestations, and I'm working on a fix now. I'll update this issue with xrefs as I build out the fix.

TL;DR: Your publishing workflow produced a perfectly valid attestation, but one that didn't include a ref claim for whatever reason. We've seen this happen before with Trusted Publishing as well as we have workarounds for it, but the workaround wasn't complete for the attestation side of things.

Apologies for any confusion this caused on your end!

xref: tlog entry: https://search.sigstore.dev/?logIndex=191974551

Yak stack:

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions