-
Notifications
You must be signed in to change notification settings - Fork 15
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[draft] add PyPI GA post #67
Conversation
Signed-off-by: William Woodruff <[email protected]>
Signed-off-by: William Woodruff <[email protected]>
Signed-off-by: William Woodruff <[email protected]>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM aside from nits!
content/pypi-attestations-ga.md
Outdated
An important piece of the story for attestations on PyPI is | ||
**default enablement**: if a project uses [Trusted Publishing], | ||
simply upgrading to [`pypa/gh-action-pypi-publish`] [v1.11.0] or newer will result | ||
in attestation generation by default, with no changes required. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This might be a bit too much detail for the Sigstore blog? Readers might not know what pypa/gh-action-pypi-publish
is. Maybe we can just say "if a project uses Trusted Publishing and the canonical GitHub Action to upload their distribution" or something like that.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Makes sense, I'll make this change in a moment!
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done, PTAL 🙂
Co-authored-by: Dustin Ingram <[email protected]> Signed-off-by: William Woodruff <[email protected]>
Co-authored-by: Dustin Ingram <[email protected]> Signed-off-by: William Woodruff <[email protected]>
Co-authored-by: Dustin Ingram <[email protected]> Signed-off-by: William Woodruff <[email protected]>
Signed-off-by: William Woodruff <[email protected]>
Co-authored-by: Dustin Ingram <[email protected]> Signed-off-by: William Woodruff <[email protected]>
Adds a short post announcing PEP 740 on PyPI, to be coordinated with the PyPI blog and ToB blog posts.
CC @haydentherapper @di