Skip to content

ci: add cryptographic supply-chain notarization for PyPI release packages - #433

Open
ProofCore-Protocol wants to merge 1 commit into
Ackee-Blockchain:mainfrom
ProofCore-Protocol:main
Open

ProofCore-Protocol wants to merge 1 commit into
Ackee-Blockchain:mainfrom
ProofCore-Protocol:main

Conversation

@ProofCore-Protocol

Copy link
Copy Markdown

Hi Ackee Blockchain team! 👋

As fellow Web3 security enthusiasts, we really appreciate the work you're doing with Wake and Solidity developer tooling.

This PR adds automated, non-intrusive supply-chain security attestation to your PyPI release workflow using ProofCore Action.

How it fits into your workflow:
Splitted poetry publish --build into explicit poetry build and poetry publish.
Between build and publish, ProofCore computes SHA-256 digests of the generated wheels and source archives in dist/* locally on the runner.
Binds the hashes to your repository's cryptographic GitHub OIDC token and anchors the proof root on-chain.
Allows security auditors and developers installing wake via PyPI to independently verify that their packages match the exact GitHub Actions build.

Zero friction & zero storage:
Runs with continue-on-error: true so it will never block your release pipeline in case of external network timeouts.
Raw code or binaries are never stored remotely (zero-storage model).

Happy to make any adjustments or answer questions! 🚀

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant