Skip to content

Is it possible/planned to add the sigstore output to the output files? #367

Answered by webknjaz
MajorTanya asked this question in Q&A
Discussion options

You must be logged in to vote

There's a plan to start uploading to GH attestations directly. Though, it requires some work.
I don't think we'll be exposing publish attestations. Though you can probably retrieve them from PyPI if you really need.
Don't disable attentions. You can't upload manually crafted ones.
If you want, you can produce signatures separately. I tend to do so myself, in separate jobs. I use GH-native, Sigstore and SLSA. I think, one example where you can find this is ansible/awx-plugins, another one would be cherrypy/cheroot.
Though, William thinks people should just drop the sigstore step..

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@MajorTanya
Comment options

@webknjaz
Comment options

Answer selected by webknjaz
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants