Skip to main content

A tool for signing Python package distributions

Reason this release was yanked:

Incompatible w/ latest Sigstore APIs

Project description

sigstore-python

CI PyPI version

⚠️ This project is not ready for general-purpose use! ⚠️

sigstore is a tool for signing and verifying Python package distributions.

Features

  • Support for signing Python package distributions using an OpenID Connect identity
  • Support for publishing signatures to a Rekor instance
  • Support for verifying signatures on Python package distributions

Installation

sigstore requires Python 3.7 or newer, and can be installed directly via pip:

python -m pip install sigstore

Usage

You can run sigstore as a standalone program, or via python -m:

sigstore --help
python -m sigstore --help

Top-level:

Usage: sigstore [OPTIONS] COMMAND [ARGS]...

Options:
  --help  Show this message and exit.

Commands:
  sign
  verify

Signing:

Usage: sigstore sign [OPTIONS] FILE [FILE ...]

Options:
  --identity-token TEXT
  --ctfe FILENAME
  --help                 Show this message and exit.

Verifying

Usage: sigstore verify [OPTIONS] FILE [FILE ...]

Options:
  --cert FILENAME       [required]
  --signature FILENAME  [required]
  --cert-email TEXT
  --help                Show this message and exit.

Licensing

sigstore is licensed under the Apache 2.0 License.

Contributing

See the contributing docs for details.

Code of Conduct

Everyone interacting with this project is expected to follow the sigstore Code of Conduct.

Security

Should you discover any security issues, please refer to sigstore's security process.

Info

sigstore-python is developed as part of the sigstore project.

We also use a slack channel! Click here for the invite link.

Project details


Release history Release notifications | RSS feed

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

sigstore-0.1.0.tar.gz (22.2 kB view details)

Uploaded Source

Built Distribution

sigstore-0.1.0-py3-none-any.whl (31.6 kB view details)

Uploaded Python 3

File details

Details for the file sigstore-0.1.0.tar.gz.

File metadata

  • Download URL: sigstore-0.1.0.tar.gz
  • Upload date:
  • Size: 22.2 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/4.0.0 CPython/3.9.12

File hashes

Hashes for sigstore-0.1.0.tar.gz
Algorithm Hash digest
SHA256 991d04732c1e9b7e6e8b9ea61cbea9c6166c54e956446dd25c4f39010e4df429
MD5 8b21ecc6d589ca4e325123fd44e6f17d
BLAKE2b-256 1719eb72f43be76311fe732a9b90741c1487207f0d87c8270becf0dae381a421

See more details on using hashes here.

Provenance

File details

Details for the file sigstore-0.1.0-py3-none-any.whl.

File metadata

  • Download URL: sigstore-0.1.0-py3-none-any.whl
  • Upload date:
  • Size: 31.6 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/4.0.0 CPython/3.9.12

File hashes

Hashes for sigstore-0.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 39a8ec8cceeb9b7728f8527fe5b6ee0f674e939d8d9042cca2a14cd2d456740a
MD5 9a1d0e0413e762790aa4dceb4202f6de
BLAKE2b-256 0f9b6c6e0a6067d93c892188470fcccc1428d349bc3b4eecc273020e8f6799d8

See more details on using hashes here.

Provenance

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page