This should not be that technically difficult but there are some complications: * As mentioned in https://github.com/pypa/gh-action-pypi-publish/issues/383 the upgrade has implications later on when [rekorv2](https://blog.sigstore.dev/rekor-v2-alpha/) is added to the sigstore signingconfig: new log entries will then come from rekorv2, and older clients will be unable to verify them * #131