Skip to content

Investigate simplifying SPEC 8 through use of pypa/gh-action-pypi-publish v1.11.0+ #359

@matthewfeickert

Description

@matthewfeickert

As noted in pypa/gh-action-pypi-publish#281, in https://github.com/pypa/gh-action-pypi-publish/ v1.11.0

every project making use of Trusted Publishing will start producing and publishing digital attestations without having to do any modifications to how they use this action.

This is great news, so a big thanks to @webknjaz and @woodruffw for this!

For some of our packages that have upcoming releases we should investigate how the attestations differ from the actions/attest-build-provenance ones and what the verification workflow is like. If we like them, then we should revise SPEC 8 to just use these automatically generated attestations, simplifying the process.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions