Skip to content

ci: enable Sigstore attestations for PyPI releases#7

Merged
JRemitz merged 1 commit intomainfrom
ci/enable-attestations
Apr 8, 2026
Merged

ci: enable Sigstore attestations for PyPI releases#7
JRemitz merged 1 commit intomainfrom
ci/enable-attestations

Conversation

@JRemitz
Copy link
Copy Markdown
Contributor

@JRemitz JRemitz commented Apr 8, 2026

Summary

  • Add attestations: true to pypa/gh-action-pypi-publish
  • Add attestations: write permission for Sigstore provenance generation
  • Each future PyPI release will include verifiable attestations tied to the GitHub Actions workflow

Test plan

  • Next tag-triggered release generates attestations on PyPI

🤖 Generated with Claude Code

Add attestations: true to pypa/gh-action-pypi-publish and
attestations: write permission so each release generates
verifiable Sigstore provenance tied to the GitHub Actions workflow.

Co-Authored-By: Claude <noreply@anthropic.com>
@JRemitz JRemitz merged commit 9d8f544 into main Apr 8, 2026
5 checks passed
@JRemitz JRemitz deleted the ci/enable-attestations branch April 8, 2026 12:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant