Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Switch away from sigstore to #7

Open
captn3m0 opened this issue Aug 12, 2024 · 3 comments
Open

Switch away from sigstore to #7

captn3m0 opened this issue Aug 12, 2024 · 3 comments

Comments

@captn3m0
Copy link
Owner

https://docs.github.com/en/actions/security-for-github-actions/using-artifact-attestations/using-artifact-attestations-to-establish-provenance-for-builds.

seems like while pypa is still suggestion the python sigstore action, the github attestations are more native, so we should move there?

@captn3m0
Copy link
Owner Author

How I hate python ecosystem fragmentation. just after upgrading from pyscaffold, because the pypa setuptools links it pointed me to are dead after 3 years.

@captn3m0
Copy link
Owner Author

captn3m0 commented Sep 2, 2024

Waiting for pypi/warehouse#15871 is probably a good idea.

@webknjaz
Copy link

webknjaz commented Sep 3, 2024

FYI, it's already possible to upload the attestations. I had to fix a minor bug in the action today but you can start uploading already if you use trusted publishing. Just bump to v1.10.1 and opt-in.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants