security(release): sign GitHub Release artifacts with Sigstore (keyless)
publish.yml github-release job now signs the wheel + sdist via sigstore/gh-action-sigstore-python (pinned v3.3.0 / 04cffa1d), keyless OIDC, and attaches the .sigstore.json bundles to the GitHub Release through the existing dist/* glob. Added id-token: write to the job for OIDC. PyPI uploads were already attested (Trusted Publishing); Scorecard's Signed-Releases check inspects GitHub Releases, which only carried bare wheels -> score 0. .sigstore.json is in Scorecard's recognized signatureExtensions. Verified: action globs ./dist/*.whl ./dist/*.tar.gz (action.py:202), auto-attach gated on release-event (we trigger on push:tags) so we upload via dist/* and set release-signing-artifacts:false. First live proof = next v* tag. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
dab8d29645
commit
076110a2fb
@@ -41,12 +41,24 @@ jobs:
|
||||
runs-on: ubuntu-latest
|
||||
permissions:
|
||||
contents: write
|
||||
id-token: write # keyless Sigstore signing (OIDC); no signing key exists
|
||||
steps:
|
||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
||||
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
|
||||
with:
|
||||
name: dist
|
||||
path: dist/
|
||||
- name: Sign artifacts with Sigstore (keyless, OIDC)
|
||||
# Produces dist/<artifact>.sigstore.json bundles next to each wheel/sdist.
|
||||
# The 'gh release create dist/*' step below then attaches them to the
|
||||
# GitHub Release, which is where Scorecard's Signed-Releases check looks.
|
||||
# release-signing-artifacts is disabled: the action's own auto-attach only
|
||||
# fires on a 'release: published' event, but we trigger on 'push: tags',
|
||||
# so we upload the bundles ourselves via the dist/* glob.
|
||||
uses: sigstore/gh-action-sigstore-python@04cffa1d795717b140764e8b640de88853c92acc # v3.3.0
|
||||
with:
|
||||
inputs: ./dist/*.tar.gz ./dist/*.whl
|
||||
release-signing-artifacts: false
|
||||
- name: Extract latest CHANGELOG section
|
||||
run: |
|
||||
# Grab the topmost "## [...]" block from CHANGELOG.md as release notes.
|
||||
|
||||
Reference in New Issue
Block a user