Skip to content
Discussion options

You must be logged in to vote

The project results include both source code and any generated deliverables where applicable (e.g., executables, packages, and containers)

Hi @andife ! This action will sign over the artifacts it uploads to PyPI. If these artifacts (source distributions and wheels) are all the "generated derivables" of the project, then that should cover it.

How Could I verify the signatures in that case?

You can use pypy-attestations

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@andife
Comment options

Answer selected by andife
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants