ci: add cryptographic supply-chain notarization for PyPI release packages - #433
Open
ProofCore-Protocol wants to merge 1 commit into
Open
ProofCore-Protocol wants to merge 1 commit into
ProofCore-Protocol wants to merge 1 commit into
Conversation
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Hi Ackee Blockchain team! 👋
As fellow Web3 security enthusiasts, we really appreciate the work you're doing with Wake and Solidity developer tooling.
This PR adds automated, non-intrusive supply-chain security attestation to your PyPI release workflow using ProofCore Action.
How it fits into your workflow:
Splitted poetry publish --build into explicit poetry build and poetry publish.
Between build and publish, ProofCore computes SHA-256 digests of the generated wheels and source archives in dist/* locally on the runner.
Binds the hashes to your repository's cryptographic GitHub OIDC token and anchors the proof root on-chain.
Allows security auditors and developers installing wake via PyPI to independently verify that their packages match the exact GitHub Actions build.
Zero friction & zero storage:
Runs with continue-on-error: true so it will never block your release pipeline in case of external network timeouts.
Raw code or binaries are never stored remotely (zero-storage model).
Happy to make any adjustments or answer questions! 🚀