Pre-PEP discussion: Stop providing GPG signatures for CPython artifacts

The package maintainers never got around to setting them up. Or didn’t consider them to be important.

I’ll file bugs requesting the support and we’ll see how things go. I think we’re broadly in agreement with the goals here. It’s probably mostly a matter of getting the right tooling packaged and convincing people that sigstore is worth the effort of implementation in Debian package tooling.

1 Like