tree 25fc64f369fa8656d0bb520671808a9fe6df1cef parent 1b0f12e405ab91f1fdd8f5d986e34dc8aa5d18d8 author Alina Schanz 1788873739 +0200 committer Alina Schanz 1788873739 +0200 gpgsig -----BEGIN PGP SIGNATURE----- iJEEABYKADkWIQQXukw5NFGlaze47bvxpkdLQx3zqwUCaqAMCxsUgAAAAAAEAA5t YW51MiwyLjUrMS4xMiwyLDEACgkQ8aZHS0Md86vTZgD/XRNPablLwvWixjqkT01w VtM9xO2QH68feH9vqoVz2tcBAK+utaEyaU6octs0punT20W93kjbgMmnqK+XEhZs ldoD =XmqD -----END PGP SIGNATURE----- release: checksums, an opentimestamps proof and a build provenance attestation on every release; the openssf scorecard release.yml now writes SHA256SUMS next to the sdist and the wheel, stamps it with opentimestamps (the proof is attached as it is; it completes on its own once a bitcoin block includes the calendar's root) and asks github for a build provenance attestation of both files. scorecard.yml runs the openssf scorecard weekly and on pushes to main and publishes the result; the readme carries the badge and a "verify a release" section with the three commands.