fohrloop, to python
@fohrloop@fosstodon.org avatar

Can sigtore signatures be uploaded to PyPI, and is there / would there be any use for them?

I was reading through https://packaging.python.org/en/latest/guides/publishing-package-distribution-releases-using-github-actions-ci-cd-workflows/ and noticed the .sigstore files were only uploaded to GitHub Releases.

phillmv, to random
@phillmv@hachyderm.io avatar

I can finally talk about what we've been working on for the past two years(!)

Using , GitHub now supports artifact signing, which allows you to create unforgeable provenance guarantees for any software you build inside Actions.

It's been a heck of a ride, & you can read more about (and learn how to use it) here:

https://github.blog/2024-05-02-introducing-artifact-attestations-now-in-public-beta/

sethmlarson, to python
@sethmlarson@fosstodon.org avatar

Happy friday! 🎉 Just published the report for this week, updates on registration for @ThePSF, for artifacts, and other updates.

https://sethmlarson.dev/security-developer-in-residence-weekly-report-5

Foxboron, to random
@Foxboron@chaos.social avatar

Hrm,

I think I should write a bit about the "rapid" adoption of sigstore and the possible problem domains we might have in the future.

It's not like this boding very well for things like Reproducible Builds if we expect a OIDC issuer to continue living for a reasonable amount of years under the same domain.. with the same version... key rotation and... and...

sethmlarson, to python
@sethmlarson@fosstodon.org avatar

The #Sigstore signatures for #Python are now completely verifiable as documented, thanks to all the release managers who helped make this happen!

https://www.python.org/download/sigstore

https://github.com/sethmlarson/verify-python-release-signatures/

risottobias, to random

what if #sigstore #rekor or #letsencrypt #certificatetransparency distributed that info via gossip, DHT, or pubsub models?

I actually like the centralized ~3 entities, and it's great that it's not taking up huge amounts of CPU to do (compared to a proof of work)

but still... what if such data was discovered and published like a magnet link?

elijahwilson, to random
@elijahwilson@fosstodon.org avatar

It makes me so happy to see mentioned at ! There's still a long road to make this as easy as verifying when doing a pip install foo, but this is great progress. 🙌

  • All
  • Subscribed
  • Moderated
  • Favorites
  • anitta
  • thenastyranch
  • magazineikmin
  • everett
  • InstantRegret
  • rosin
  • Youngstown
  • slotface
  • love
  • khanakhh
  • kavyap
  • tacticalgear
  • GTA5RPClips
  • DreamBathrooms
  • megavids
  • modclub
  • mdbf
  • tester
  • Durango
  • ethstaker
  • osvaldo12
  • cubers
  • ngwrru68w68
  • provamag3
  • normalnudes
  • Leos
  • cisconetworking
  • JUstTest
  • All magazines