release: attest the sdist provenance, attach the bundle to the release - #216
Merged
ThomasWaldmann merged 1 commit intoAug 31, 2026
Merged
Conversation
Give the sdist a build provenance attestation via actions/attest-build-provenance, like borg does for its sdist and binaries, so that anybody can check that the file on PyPI/GitHub was built by this workflow, from this repository, at this tag. Additionally upload the sigstore bundle the action produces as a release asset next to the sdist, so the attestation can also be verified offline and does not depend on the GitHub attestations API being reachable. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds a build provenance attestation to the release workflow, like borg
already does for its sdist and binaries (
actions/attest-build-provenancein
.github/workflows/release.yml/ci.ymlthere).the
releasejob getsid-token: writeandattestations: writethe sdist is attested after it was built and checked
the sigstore bundle the action writes (
.sigstore.jsonl) is uploaded asa release asset next to the sdist, so the attestation can be verified
offline / without the GitHub attestations API:
the draft release notes tell users about both
Only the sdist goes to PyPI, the
.jsonlis a GitHub release asset only.zizmor .is clean.🤖 Generated with Claude Code