Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ci: Add GitHub artifact attestations to package distribution #1096

Merged

Conversation

matthewfeickert
Copy link
Contributor

@matthewfeickert matthewfeickert commented May 22, 2024

Verification of artifact attestations can be done via the gh attestation verify CLI API, added in v2.49.0.

@matthewfeickert
Copy link
Contributor Author

@lgray @nsmith- this is ready for review. Let me know if you have any questions. c.f. scikit-hep/pyhf#2473 for additional reference.

@lgray
Copy link
Collaborator

lgray commented May 26, 2024

Thanks @matthewfeickert proper signing is a correct thing to have.

@lgray lgray merged commit 825e7e9 into CoffeaTeam:master May 26, 2024
15 checks passed
@matthewfeickert matthewfeickert deleted the ci/add-artifact-attestations branch May 26, 2024 17:56
This pull request was closed.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants