Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Document PEP740 attestations #17043

Closed
QuLogic opened this issue Nov 6, 2024 · 2 comments
Closed

Document PEP740 attestations #17043

QuLogic opened this issue Nov 6, 2024 · 2 comments
Labels
feature request requires triaging maintainers need to do initial inspection of issue

Comments

@QuLogic
Copy link

QuLogic commented Nov 6, 2024

What's the problem this feature will solve?
gh-action-pypi-publish is now advertising that you can use PEP740 attestations, that are now on by default. This is not documented or explained anywhere.

Describe the solution you'd like
Neither https://docs.pypi.org/trusted-publishers/using-a-publisher/ nor https://docs.pypi.org/trusted-publishers/security-model/ describe PEP740 or what attestations do.
https://pypi.org/help/ does not mention it either.

I don't see any indication how to upload attestations (though I understand it's on by default now, so probably I don't need to do anything.) I also don't see any indication of where the attestations go and how to verify that they exist and are correct.

@QuLogic QuLogic added feature request requires triaging maintainers need to do initial inspection of issue labels Nov 6, 2024
@di
Copy link
Member

di commented Nov 6, 2024

This is in progress with #16398.

Closing as a duplicate of #15871.

@di di closed this as completed Nov 6, 2024
@QuLogic
Copy link
Author

QuLogic commented Nov 6, 2024

Ah sorry, I looked for "PEP740", which apparently didn't catch "PEP 740".

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
feature request requires triaging maintainers need to do initial inspection of issue
Projects
None yet
Development

No branches or pull requests

2 participants