Skip to content

docs: stop recommending pip --verify-attestations - #530

Open
HarshRajSinghania wants to merge 4 commits into
darnitdevorg:mainfrom
HarshRajSinghania:docs/fix-pip-verify-attestations
Open

HarshRajSinghania wants to merge 4 commits into
darnitdevorg:mainfrom
HarshRajSinghania:docs/fix-pip-verify-attestations

Conversation

@HarshRajSinghania

@HarshRajSinghania HarshRajSinghania commented Sep 30, 2026 •

Copy link
Copy Markdown

Fixes #520.

Summary

docs/install/pypi.md told users to run pip install --verify-attestations. pip has no such option (confirmed against pip install --help on pip 24.x; the issue reporter also checked 26.2.1), so the documented command fails.

Motivation

Users following the PyPI install guide cannot verify PEP 740 attestations with the command that was written down.

Implementation

  • Replaced the "One-step verification with pip" section with a pypi-attestations verify pypi flow against a downloaded wheel, as suggested in the issue.
  • Left the existing manual sigstore section in place.
  • Updated the packaging contract smoke-test line that repeated the same invalid flag.
  • Did not change packaging/container/Dockerfile; that comment refers to cosign verify-attestations, which is a different tool.

The --repository argument now matches the post-move signing identity documented in packaging/README.md (darnitdevorg/darnit). The other kusari-oss/darnit identity lines in docs/install/pypi.md were updated the same way. specs/012-packaging-distribution/research.md no longer mentions the nonexistent pip flag.

Testing

  • Searched the tree for verify-attestations / One-step verification.
  • Confirmed python3 -m pip install --help lists no attestation-related option (pip 24.0).
  • Docs-only change; no unit tests apply.

AI assistance

Drafted with AI assistance (Grok) and reviewed before pushing. The pip flag finding was checked against pip install --help.

Fixes darnitdevorg#520. pip has no such flag; document pypi-attestations instead.
@Marc-cn

Marc-cn commented Sep 30, 2026

Copy link
Copy Markdown
Collaborator

Thanks,the underlying point is right, pip has no --verify-attestations. Three things:

  • DCO is failing: git commit -s --amend then force-push
  • Could you fill in the "AI assistance" section of the PR template?
  • I'll approve the CI run so we can see it green

On content: use darnitdevorg/darnit, not kusari-oss. Per packaging/README.md:7, releases cut after the org move sign under the new identity, and PyPI publishing isn't live yet (#519), so anything users verify will be darnitdevorg. The four remaining kusari-oss references in pypi.md are stalefixing them here is fineor leave them and I'll open a separate issue.

@mlieberman85 mlieberman85 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for catching this. The pypi-attestations verify pypi syntax is right. Three things:

  1. DCO is failing; please sign off your commits.
  2. The AI-assistance section of the PR template is missing; please fill it in.
  3. --repository https://github.com/kusari-oss/darnit needs to be darnitdevorg/darnit. Releases are signed under the new org (see packaging/README.md). If you're up for it, the other kusari-oss lines in pypi.md could move too.

Minor: specs/012-packaging-distribution/research.md still mentions the old flag.

Drafted with Claude Code; reviewed and posted by me.

@HarshRajSinghania

Copy link
Copy Markdown
Author

Updated the docs on docs/fix-pip-verify-attestations:

  • --repository and the other kusari-oss/darnit signing-identity lines in docs/install/pypi.md now use darnitdevorg/darnit (same change in the publish contract).
  • specs/012-packaging-distribution/research.md no longer mentions pip install --verify-attestations; it points at pypi-attestations verify pypi.
  • Filled in an AI-assistance section on the PR body.

Head is a8bd81a. I did not amend the existing commit for DCO sign-off, because that needs a force-push. Happy to sign off if you want that rewrite.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

docs/install/pypi.md recommends 'pip install --verify-attestations', which pip does not have

3 participants