{"repo":"sigstore/gh-action-sigstore-python","free":true,"listed":false,"github":"https://github.com/sigstore/gh-action-sigstore-python","clone":"git clone https://github.com/sigstore/gh-action-sigstore-python.git","description":"A GitHub Action for sigstore-python","language":"Python","stars":71,"topics":["codesigning","github-actions","security","supply-chain"],"license":"Apache-2.0","category":"security-tools","readme_excerpt":"gh-action-sigstore-python ========================= This GitHub Action uses sigstore-python to generate Sigstore signatures. gh-action-sigstore-python is the easiest way to integrate Sigstore into your CI system and can be used for not only Python projects, but projects in other languages as well. [!IMPORTANT] Are you publishing a package to PyPI? If so, you do not need this action : pypa/gh-action-pypi-publish will handle signing for you! Index Usage Configuration ⚠️ Internal options ⚠️ Licensing Code of Conduct Usage Simply add sigstore/gh-action-sigstore-python to one of your workflows: Note: Your workflow must have permission to request the OIDC token to authenticate with. This can be done by setting id-token: write on your job (as above) or workflow. More information about permission settings can be found here. Configuration gh-action-sigstore-python takes a variety of configuration inputs, most of which are optional. inputs The inputs setting controls what files sigstore-python signs. At least one input must be provided unless release-signing-artifacts is set to true on release events. To sign one or more files: The inputs argument also supports file globbing: Multiple lines are fine, and whitespace in filenames can also be escaped using POSIX shell lexing rules: [!NOTE]\\ In versions of this action before 2.0.0, the inputs setting allowed for shell expansion. This was unintentional, and was removed with 2.0.0. identity-token Default : Empty (the GitHub Actions credentia","default_branch":null,"files":null,"tree":[],"storefront":"/r/sigstore","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/sigstore/gh-action-sigstore-python/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}