actions / actions/setup-python
Do Sigstore Verification For Python TarBall
未关闭
还没有人认领这个 Issue。
feature request
- 主要语言
- TypeScript
- 星标
- 2.2k
- 派生
- 739
- 平均合并
- 6 天 18 小时
- 30 天内合并 PR
- 1
描述
Description:
Verify sigstore signatures of python releases at https://github.com/actions/python-versions
Python releases are signed via Sigstore .
Github also announced to increasingly adopt sigstore
Justification:
If we verify the signatures for the downloaded python releases, the supply chain security would be greatly improved.
Are you willing to submit a PR?
Yes ! I would really love to do it.
贡献指南
这个仓库没有索引到贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
调研方向
未指定文件或测试。首先跟踪 setup-python 如何从 actions/python-versions 下载 Python 发行版,然后查看链接的 Python Sigstore 指南,并确定签名验证应放在哪里。完成的标准是:下载的 Python 发行版在使用前已通过 Sigstore 签名验证。
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- github-actions, python, typescript
- 领域
- devops, security
- Issue 类型
- 功能
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 活跃度
- 停滞
- 描述清晰度
- 基本清楚
- 新手友好度
- 35/100