-
Notifications
You must be signed in to change notification settings - Fork 664
Closed
Milestone
Description
Hi! I package this project for Arch Linux.
With the recent policy change, PyPi broke the reproducibility of downstreams: https://blog.pypi.org/posts/2023-05-23-removing-pgp/
As signatures are now no longer available on the platform, builds of projects from there are failing. This is a super sad state of affairs for downstream transparency and verification and we'll have to work through quite a lot of tickets such as this one: https://bugs.archlinux.org/task/79083
Do you plan on providing signatures for tarballs on github going forward? If so, doing a release would unblock me on that topic.
Thanks for you consideration!
Metadata
Metadata
Assignees
Labels
No labels