Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Verified creator status for pypa #94

Closed
juhoinkinen opened this issue Feb 15, 2022 · 23 comments
Closed

Verified creator status for pypa #94

juhoinkinen opened this issue Feb 15, 2022 · 23 comments
Assignees
Labels
enhancement New feature or request help wanted Extra attention is needed question Further information is requested

Comments

@juhoinkinen
Copy link

juhoinkinen commented Feb 15, 2022

Hi!

Could the pypa organization request the "verified creator" status for GitHub Marketplace?

I see pypa already has the domain verification for www.pypa.io, but that's different than the verified creator status (seems like the domain verification is one condition for the creator status).

The verified creator status would ease the use of this and all pypa's Actions, as organizations/repositories may choose to allow running only Actions by "verified creators" (or by GitHub or those added to a custom allow list). Also on Marketplace search there is a filter for Actions by verified creators.

@webknjaz
Copy link
Member

Hey @pradyunsg @di @ewdurbin, could you look into requesting the verified creator status for @pypa? The instructions are here https://docs.github.com/en/developers/github-marketplace/github-marketplace-overview/applying-for-publisher-verification-for-your-organization.

@webknjaz webknjaz added enhancement New feature or request help wanted Extra attention is needed question Further information is requested labels Jul 25, 2022
@ewdurbin
Copy link
Member

Seems we just need a verified public email address for the PyPA... but I'm really not sure what the ideal one would be.

@ewdurbin
Copy link
Member

I created info@pypa.io, and have requested verification.

@webknjaz
Copy link
Member

Thanks Ee! I'll keep this issue open until we hear back from GitHub.

@ewdurbin
Copy link
Member

Verification is active.

@webknjaz
Copy link
Member

@ewdurbin the marketplace page still shows up as unverified. Could you check why?

@ewdurbin
Copy link
Member

@webknjaz not sure what else there is to do.

pub-ver

maybe it is not retroactive, perhaps a new release would show verification?

@webknjaz
Copy link
Member

webknjaz commented Aug 9, 2022

maybe it is not retroactive, perhaps a new release would show verification?

Yeah, you must be right. The status hasn't changed, but I'll try to remember to check again after making a new release.

@webknjaz
Copy link
Member

UPD: I asked to perform the same procedure in another organization and the admins couldn't because they got There must be 1 or more GitHub/OAuth App registered by the organization to request publisher verification. This makes me think that maybe GH only shows this status for Apps but not Actions... It's not clear.

@juhoinkinen
Copy link
Author

It might be that the process to get the status badge for Actions is different than for Apps, and it would be necessary to participate in GitHub’s Partner program. :(

@webknjaz
Copy link
Member

webknjaz commented Sep 2, 2022

Yeah, that appears to be the case.

@webknjaz
Copy link
Member

Here's what GH support replied me:

Hello Sviatoslav,

Thank you for reaching out to GitHub Support! I'm sorry to hear about any confusion that came from these Marketplace processes.

Currently, there is no public process for applying to be a verified creator in regards to publishing actions. The Marketplace documentation mentions that verification is only available to select GitHub partners:

GitHub verifies some partner organizations and these are shown as verified creators.

The documented process you mention for applying for publisher verification is exclusive to GitHub App publishing.

Please let me know if you have any additional questions or concerns I can assist with!

Best,

Arthur
GitHub Support

@webknjaz
Copy link
Member

@di @ewdurbin I think the PSF/PyPA should already be partnering w/ GH in the context of Warehouse's integration with https://docs.github.com/en/developers/overview/secret-scanning-partner-program. Could that help us get the PyPA org verified for actions? Any ideas?

FWIW GitHub's own docs already showcase the use of this action in their examples of publishing to various registries so it only seems reasonable for this project to be verified.

@di
Copy link
Sponsor Member

di commented Sep 14, 2022

I think that makes sense. I've applied on behalf of the PyPA and included that as justification, let's see what happens.

@ewdurbin
Copy link
Member

Thanks @di. I can confirm the application receipt made it to the verified email for the PyPA org. I’ll update if any further correspondence comes through.

@webknjaz
Copy link
Member

webknjaz commented Sep 14, 2022

Thanks everyone 🙏

@ewdurbin
Copy link
Member

Signed paperwork from GH. Awaiting further updates.

@ewdurbin
Copy link
Member

GH says we are now good to go. Has anything in the way its displayed changed?

@di
Copy link
Sponsor Member

di commented Sep 15, 2022

Doesn't seem like it:
image

Maybe there's some sort of review period?

@di
Copy link
Sponsor Member

di commented Apr 17, 2023

Reopening because while the PyPA org appears to be a verified publisher:

image

the action itself is still not verified:

image

The docs at https://docs.github.com/en/apps/publishing-apps-to-github-marketplace/github-marketplace-overview/about-marketplace-badges#for-github-actions say:

Actions with the , or verified creator badge, indicate that GitHub has verified the creator of the action as a partner organization. Partners can email partnerships@github.com to request the verified creator badge.

@ewdurbin, were you in touch with this email address before, or do we need to reach out to them as the last step here?

@di di reopened this Apr 17, 2023
@di di mentioned this issue Apr 17, 2023
@di
Copy link
Sponsor Member

di commented Jun 12, 2023

@ewdurbin post-pycon ping here!

@ewdurbin
Copy link
Member

email'd

@ewdurbin
Copy link
Member

IMG_1096

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request help wanted Extra attention is needed question Further information is requested
Projects
None yet
Development

No branches or pull requests

5 participants