tree 072a3001c8b01be45feec211abb5624296655ec8 parent 9e26dbf82752b2210715bc6f5b24969e4b7de3cf author Alina Schanz 1788873740 +0200 committer Alina Schanz 1788873740 +0200 gpgsig -----BEGIN PGP SIGNATURE----- iJEEABYKADkWIQQXukw5NFGlaze47bvxpkdLQx3zqwUCaqAMDBsUgAAAAAAEAA5t YW51MiwyLjUrMS4xMiwyLDEACgkQ8aZHS0Md86u6HgEAvfCxWYfWxP/AJ3PagiBK CIwcq0/ihtcjkyLQEuze9A4BAJfeWSD4a6P+zhauwM9F0K3cIH4nzwbwjKKvxPYo H5YB =dFAJ -----END PGP SIGNATURE----- release: checksums, an opentimestamps proof and a build provenance attestation on every release; the openssf scorecard release.yml now writes SHA256SUMS next to the sdist and the wheel, stamps it with opentimestamps (the proof is attached as it is; it completes on its own once a bitcoin block includes the calendar's root) and asks github for a build provenance attestation of both files. scorecard.yml runs the openssf scorecard weekly and on pushes to main and publishes the result; the readme carries the badge and a "verify a release" section with the three commands.