logoalt Hacker News

fc417fc802last Thursday at 6:19 AM1 replyview on HN

Maybe signed publishing or verified publishing would have been better terms?


Replies

woodruffwlast Thursday at 12:19 PM

It’s neither signed or verified, though. There’s a signature involved, but that signature is over a JWT not over the package.

(There’s an overlaid thing called “attestations” on PyPI, which is a form of signing. But Trusted Publishing itself isn’t signing.)

show 1 reply