tree 36e8c44527244a0a0f38344b85fb4e584cb41cd8 parent ebf54f36389eda2d7e8211a60d12a0a8ee3324d7 author Alina Schanz 1788873740 +0200 committer Alina Schanz 1788873740 +0200 gpgsig -----BEGIN PGP SIGNATURE----- iJEEABYKADkWIQQXukw5NFGlaze47bvxpkdLQx3zqwUCaqAMDBsUgAAAAAAEAA5t YW51MiwyLjUrMS4xMiwyLDEACgkQ8aZHS0Md86taHgD/ZZq1UKhyG+gKIgDFQxba 4JgjwUuOQaJdkNjPMYtQ0lEA/1nYVSaQPNAEk5RaN4KVTgtSj5v23FD1bp9tJQIn XswJ =kChv -----END PGP SIGNATURE----- release: checksums, an opentimestamps proof and a build provenance attestation on every release; the openssf scorecard release.yml now writes SHA256SUMS next to the sdist and the wheel, stamps it with opentimestamps (the proof is attached as it is; it completes on its own once a bitcoin block includes the calendar's root) and asks github for a build provenance attestation of both files. scorecard.yml runs the openssf scorecard weekly and on pushes to main and publishes the result; the readme carries the badge and a "verify a release" section with the three commands.