Hi, Here's another shot at provenance verification API. To address your concerns, I've renamed the flag from verify-sig to verify-provenance. This should make the difference in semantics and security model clearer.
Michał Górny (4): pypi.eclass: Fix eclassdoc typo; <package> → <project> pypi.eclass: Update the @DESCRIPTION pypi.eclass: Introduce provenance verification API dev-python/pypi-attestations: Enable provenance verification dev-python/pypi-attestations/Manifest | 1 + .../pypi-attestations-0.0.27.ebuild | 1 + eclass/pypi.eclass | 135 ++++++++++++++++-- profiles/arch/amd64/use.mask | 4 + profiles/arch/base/use.mask | 4 + 5 files changed, 133 insertions(+), 12 deletions(-)
