Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Signed releases for downstreams #550

@dvzrv

Description

@dvzrv

Hi! I package this project for Arch Linux.

With the recent policy change, PyPi broke the reproducibility of downstreams: https://blog.pypi.org/posts/2023-05-23-removing-pgp/

As signatures are now no longer available on the platform, builds of projects from there are failing. This is a super sad state of affairs for downstream transparency and verification and we'll have to work through quite a lot of tickets such as this one: https://bugs.archlinux.org/task/79083

Do you plan on providing signatures for tarballs on github going forward? If so, doing a release would unblock me on that topic.

Thanks for you consideration!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions