Skip to content

Update cosign.py

Update cosign.py #102

Triggered via push January 5, 2026 21:40
Status Success
Total duration 1m 40s
Artifacts

release.yaml

on: push
Upload to PyPI
22s
Upload to PyPI
Push to Docker Hub
1m 11s
Push to Docker Hub
Fit to window
Zoom out
Zoom in

Annotations

3 warnings
Create a Trusted Publisher
A new Trusted Publisher for the currently running publishing workflow can be created by accessing the following link(s) while logged-in as an owner of the package(s):
Upgrade to Trusted Publishing
Trusted Publishers allows publishing packages to PyPI from automated environments like GitHub Actions without needing to use username/password combinations or API tokens to authenticate with PyPI. Read more: https://docs.pypi.org/trusted-publishers
attestations input ignored
The workflow was run with the 'attestations: true' input, but an explicit password was also set, disabling Trusted Publishing. As a result, the attestations input is ignored.