PyPI now supports digital attestations

Yep! The plan is to enable GitLab in short order, followed by the other currently supported Trusted Publisher providers, followed by looking into non-TP identities (like emails).

1 Like