Pre-PEP discussion: Stop providing GPG signatures for CPython artifacts

Thanks @mgorny @hroncok and @mcepl for providing feedback, this is great information to have so we can prioritize.

For having a compiled binary for Sigstore, I was pointed to the sigstore-go client as an option. In fact, the sigstore-go client already lists offline verification on their list of features. I’ll double-check that that is correct, though!

2 Likes