Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Do Sigstore Verification For Python TarBall #764

Open
sbs2001 opened this issue Nov 12, 2023 · 3 comments
Open

Do Sigstore Verification For Python TarBall #764

sbs2001 opened this issue Nov 12, 2023 · 3 comments
Labels
feature request New feature or request to improve the current logic

Comments

@sbs2001
Copy link

sbs2001 commented Nov 12, 2023

Description:

Verify sigstore signatures of python releases at https://github.com/actions/python-versions

Python releases are signed via Sigstore .
Github also announced to increasingly adopt sigstore

Justification:

If we verify the signatures for the downloaded python releases, the supply chain security would be greatly improved.

Are you willing to submit a PR?

Yes ! I would really love to do it.

@sbs2001 sbs2001 added feature request New feature or request to improve the current logic needs triage labels Nov 12, 2023
@dmitry-shibanov
Copy link
Contributor

Hello @sbs2001. Thank you four your feature request. We'll investigate it and reach to you with our decision.

@sbs2001
Copy link
Author

sbs2001 commented Nov 16, 2023

@dmitry-shibanov thanks !

@sethmlarson
Copy link

sethmlarson commented Nov 21, 2023

This would be awesome to see, setup-python would be a great consumer of such information since the number of users this action sees is likely astronomical. I've recently done an audit of existing Sigstore signatures and found them to be consistent as documented and have backfilled .sigstore bundles to old versions to make adoption easier across a wide range of Python versions.

@dmitry-shibanov It would be great to see this implemented, I'm happy to provide guidance if needed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
feature request New feature or request to improve the current logic
Projects
None yet
Development

No branches or pull requests

3 participants