Skip to content

Obtain PyPI Publish Attestation #947

@behnazh-w

Description

@behnazh-w

We need to obtain PyPI Publish Attestations when available to more accurately identify publishing workflows. We could obtain this info from deps.dev. See this package as an example: https://deps.dev/pypi/ultralytics

The provenance file should also be obtainable from PyPI: https://pypi.org/integrity/package-name/version/wheel-name/provenance, e.g., https://pypi.org/integrity/ultralytics/8.3.70/ultralytics-8.3.70-py3-none-any.whl/provenance

Metadata

Metadata

Assignees

Labels

slsa-provenanceThe issues related to SLSA provenances

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions