Codesigning and verification tool for Python packages using Sigstore
Codesigning tool for Python packages
sigstore$ sigstore sign dist/my_package-1.0.0-py3-none-any.whl$ sigstore verify dist/my_package-1.0.0-py3-none-any.whl$ sigstore sign --identity user@example.com dist/my_package-1.0.0.tar.gz