Repository navigation
docs: stop recommending pip --verify-attestations - #530
HarshRajSinghania wants to merge 4 commits into
Conversation
Fixes darnitdevorg#520. pip has no such flag; document pypi-attestations instead.
|
Thanks,the underlying point is right,
On content: use |
mlieberman85
left a comment
There was a problem hiding this comment.
Thanks for catching this. The pypi-attestations verify pypi syntax is right. Three things:
- DCO is failing; please sign off your commits.
- The AI-assistance section of the PR template is missing; please fill it in.
--repository https://github.com/kusari-oss/darnitneeds to bedarnitdevorg/darnit. Releases are signed under the new org (seepackaging/README.md). If you're up for it, the otherkusari-osslines inpypi.mdcould move too.
Minor: specs/012-packaging-distribution/research.md still mentions the old flag.
Drafted with Claude Code; reviewed and posted by me.
|
Updated the docs on
Head is a8bd81a. I did not amend the existing commit for DCO sign-off, because that needs a force-push. Happy to sign off if you want that rewrite. |
Fixes #520.
Summary
docs/install/pypi.mdtold users to runpip install --verify-attestations. pip has no such option (confirmed againstpip install --helpon pip 24.x; the issue reporter also checked 26.2.1), so the documented command fails.Motivation
Users following the PyPI install guide cannot verify PEP 740 attestations with the command that was written down.
Implementation
pypi-attestations verify pypiflow against a downloaded wheel, as suggested in the issue.sigstoresection in place.packaging/container/Dockerfile; that comment refers tocosign verify-attestations, which is a different tool.The
--repositoryargument now matches the post-move signing identity documented inpackaging/README.md(darnitdevorg/darnit). The otherkusari-oss/darnitidentity lines indocs/install/pypi.mdwere updated the same way.specs/012-packaging-distribution/research.mdno longer mentions the nonexistent pip flag.Testing
verify-attestations/One-step verification.python3 -m pip install --helplists no attestation-related option (pip 24.0).AI assistance
Drafted with AI assistance (Grok) and reviewed before pushing. The pip flag finding was checked against
pip install --help.