jazzband/pip-tools

Research ways to support verifying the PEP 740 digital attestations early

Open

#2,080 opened on 2024年4月26日

GitHub で見る
 (3 comments) (0 reactions) (0 assignees)Python (7,230 stars) (605 forks)batch import
PR wantedenhancementfeaturehasheshelp wantedneeds discussionneeds more infopackaging

説明

The upstream is moving forward now — https://github.com/pypi/warehouse/issues/15871 — so should pip-tools. I don't yet know what it'll look like here but we need to watch for the opportunities to integrate a preliminary support for such security-related features.

コントリビューターガイド

Research ways to support verifying the PEP 740 digital attestations early · jazzband/pip-tools#2080 | Good First Issue