Skip to content

Conversation

facutuesca
Copy link
Collaborator

Checklist

Making a release

  • Bump the version in src/pypi_attestations/__init__.py
  • Add a new subheading in the CHANGELOG for the new version
  • Add a link at the bottom of the CHANGELOG for the diff of the new version

@facutuesca facutuesca requested a review from di October 14, 2025 10:05
CHANGELOG.md Outdated

### Changed

- Upgraded `sigstore` dependency to `>=4.0.0`
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This maybe too much detail but could mention that rekor version is forced to 1: annotations created with 0.0.28 will only contain rekor v1 entries even after the sigstore public good instance starts offering v2 for signing

Copy link
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

done!

Copy link
Collaborator

@di di left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'd like to move this into the pypi org (and update docs/links) before we make this release.

Signed-off-by: Facundo Tuesca <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants