Path: csiph.com!weretis.net!feeder8.news.weretis.net!newsfeed.xs3.de!news.samoylyk.net!gothmog.csi.it!bofh.it!news.nic.it!robomod From: Simon Josefsson Newsgroups: linux.debian.bugs.dist,linux.debian.devel,linux.debian.maint.python Subject: Bug#1111990: ITP: python-pypi-attestations -- convert between Sigstore Bundles and PEP 740 Attestation objects Date: Sun, 24 Aug 2025 22:30:02 +0200 Message-ID: X-Original-To: submit@bugs.debian.org X-Mailbox-Line: From debian-bugs-dist-request@lists.debian.org Sun Aug 24 20:21:08 2025 Old-Return-Path: X-Spam-Flag: NO X-Spam-Score: -0.899 Reply-To: Simon Josefsson , 1111990@bugs.debian.org Resent-To: debian-bugs-dist@lists.debian.org Resent-Cc: debian-devel@lists.debian.org, debian-python@lists.debian.org, wnpp@debian.org X-Debian-Pr-Message: report 1111990 X-Debian-Pr-Package: wnpp Openpgp: id=B1D2BD1375BECB784CF4F8C4D73CF638C53C06BE; url=https://josefsson.org/key-20190320.txt X-Hashcash: 1:23:250824:submit@bugs.debian.org::HTmlhHAY4PZ0+AlS:4unl User-Agent: Gnus/5.13 (Gnus v5.13) MIME-Version: 1.0 Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha256; protocol="application/pgp-signature" X-Debian-Message: from BTS X-Mailing-List: archive/latest/1920449 List-ID: List-URL: Approved: robomod@news.nic.it Lines: 53 Organization: linux.* mail to news gateway Sender: robomod@news.nic.it X-Original-Date: Sun, 24 Aug 2025 22:19:00 +0200 X-Original-Message-ID: <87o6s4a2x7.fsf@josefsson.org> Xref: csiph.com linux.debian.bugs.dist:1257938 linux.debian.devel:118685 linux.debian.maint.python:17023 --=-=-= Content-Type: text/plain Package: wnpp Severity: wishlist Owner: Simon Josefsson X-Debbugs-Cc: debian-devel@lists.debian.org, debian-python@lists.debian.org * Package name : python-pypi-attestations Version : 0.0.27 * URL : https://github.com/trailofbits/pypi-attestations * License : Apache 2.0 Programming Lang: Python Description : convert between Sigstore Bundles and PEP 740 Attestation objects A library to generate and convert between Sigstore Bundles and [PEP 740] Attestation objects. Use these APIs to create a PEP 740-compliant `Attestation` object by signing a Python artifact (i.e: sdist or wheel files), and to verify an `Attestation` object against a Python artifact. https://salsa.debian.org/python-team/packages/python-pypi-attestations/ /Simon --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQNoBAEWCAMQFiEEo8ychwudMQq61M8vUXIrCP5HRaIFAmirc7QUHHNpbW9uQGpv c2Vmc3Nvbi5vcmfCHCYAmDMEXJLOtBYJKwYBBAHaRw8BAQdACIcrZIvhrxDBkK9f V+QlTmXxo2naObDuGtw58YaxlOu0JVNpbW9uIEpvc2Vmc3NvbiA8c2ltb25Aam9z ZWZzc29uLm9yZz6IlgQTFggAPgIbAwULCQgHAgYVCAkKCwIEFgIDAQIeAQIXgBYh BLHSvRN1vst4TPT4xNc89jjFPAa+BQJn0XQkBQkNZGbwAAoJENc89jjFPAa+BtIA /iR73CfBurG9y8pASh3cbGOMHpDZfMAtosu6jbpO69GHAP4p7l57d+iVty2VQMsx +3TCSAvZkpr4P/FuTzZ8JZe8BrgzBFySz4EWCSsGAQQB2kcPAQEHQOxTCIOaeXAx I2hIX4HK9bQTpNVei708oNr1Klm8qCGKiPUEGBYIACYCGwIWIQSx0r0Tdb7LeEz0 +MTXPPY4xTwGvgUCZ9F0SgUJDWRmSQCBdiAEGRYIAB0WIQSjzJyHC50xCrrUzy9R cisI/kdFogUCXJLPgQAKCRBRcisI/kdFoqdMAQCgH45aseZgIrwKOvUOA9QfsmeE 8GZHYNuFHmM9FEQS6AD6A4x5aYvoY6lo98pgtw2HPDhmcCXFItjXCrV4A0GmJA4J ENc89jjFPAa+wUUBAO64fbZek6FPlRK0DrlWsrjCXuLi6PUxyzCAY6lG2nhUAQC6 qobB9mkZlZ0qihy1x4JRtflqFcqqT9n7iUZkCDIiDbg4BFySz2oSCisGAQQBl1UB BQEBB0AxlRumDW6nZY7A+VCfek9VpEx6PJmdJyYPt3lNHMd6HAMBCAeIfgQYFggA JgIbDBYhBLHSvRN1vst4TPT4xNc89jjFPAa+BQJn0XTSBQkNZGboAAoJENc89jjF PAa+0M0BAPPRq73kLnHYNDMniVBOzUdi2XeF32idjEWWfjvyIJUOAP4wZ+ALxIeh is3Uw2BzGZE6ttXQ2Q+DeCJO3TPpIqaXDAAKCRBRcisI/kdFogsJAP96ynx8jm9U zytatukoLc95lmyDxOoch+Om5ZIGiEU9xAD+NqcShVTBkwBR7eATmCeTnqqcsqzi mfgbTtBKN4zW6QI= =W6mQ -----END PGP SIGNATURE----- --=-=-=--