Email or username:

Password:

Forgot your password?
Simon Willison

Posted some notes on the new PyPI digital attestations feature released today, providing digital signatures that help demonstrate that the package you are downloading from PyPI was built from a specific version of the underlying code on GitHub simonwillison.net/2024/Nov/14/

2 comments
Hugo 雨果

@simon I understand what this does, but I don’t understand the value of it. It provides validation that the build happened on MS’s server and that they used used a specific checkout. But if builds are not reproducible (eg: use unchecksumed external resources), this guarantees nothing. If builds are properly reproducible, what value does the attestation add?

Simon Willison

@whynothugo I like that I can see the git commit hash that was used for the build, which means I can review the code myself

Go Up