Hi,

Here's another shot at provenance verification API.  To address your
concerns, I've renamed the flag from verify-sig to verify-provenance.
This should make the difference in semantics and security model clearer.


Michał Górny (4):
  pypi.eclass: Fix eclassdoc typo; <package> → <project>
  pypi.eclass: Update the @DESCRIPTION
  pypi.eclass: Introduce provenance verification API
  dev-python/pypi-attestations: Enable provenance verification

 dev-python/pypi-attestations/Manifest         |   1 +
 .../pypi-attestations-0.0.27.ebuild           |   1 +
 eclass/pypi.eclass                            | 135 ++++++++++++++++--
 profiles/arch/amd64/use.mask                  |   4 +
 profiles/arch/base/use.mask                   |   4 +
 5 files changed, 133 insertions(+), 12 deletions(-)


Reply via email to