Skip to content

Sign what a release ships - #12

Merged
DenisDrobyshev merged 1 commit into
masterfrom
add/release-provenance
Sep 18, 2026
Merged

DenisDrobyshev merged 1 commit into
masterfrom
add/release-provenance

Conversation

@DenisDrobyshev

Copy link
Copy Markdown
Member

The release already carries the distributions; what it did not carry was anything tying them to the run that produced them.

The attestation goes in the build job, not in the one that creates the release — a later job holding the same artefact can only attest that it downloaded it.

Verify with gh attestation verify <file> --repo DrobyshevDev/mlango. PyPI-side PEP 740 attestations are untouched.

Signed-Releases is one of the five checks scoring 0 on this repository's Scorecard (currently 6.3, the highest in the organisation).

Not exercised by this PR: the release path only runs on a published release.

The release already carries the distributions. What it did not carry was
anything tying them to the run that produced them, so "this wheel came from
that commit" was a claim with nothing behind it.

The attestation is produced in the build job rather than in the job that creates
the release: a later job holding the same artefact can only attest that it
downloaded it, which is not the claim anyone wants to verify.

PyPI-side PEP 740 attestations are unchanged; gh-action-pypi-publish produces
those by default under Trusted Publishing.
@DenisDrobyshev
DenisDrobyshev merged commit 97440f7 into master Sep 18, 2026
16 checks passed
@DenisDrobyshev
DenisDrobyshev deleted the add/release-provenance branch September 18, 2026 20:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant