-
Notifications
You must be signed in to change notification settings - Fork 2
Expand file tree
/
Copy pathREADME.env
More file actions
123 lines (85 loc) · 4.42 KB
/
Copy pathREADME.env
File metadata and controls
123 lines (85 loc) · 4.42 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
dp-python-lib — Release Artifacts and Verification
==================================================
This repository publishes versioned dp-python-lib Python distributions via
GitHub Releases. Each release corresponds to a Git tag of the form:
rel-<version>
Example:
rel-1.16.0
------------------------------------------------------------
Release Contents
------------------------------------------------------------
Each release contains:
dp_python_lib-<version>-py3-none-any.whl
The wheel. This is what you install.
dp_python_lib-<version>.tar.gz
The source distribution.
SHA256SUMS
SHA-256 checksums for the two files above, in sha256sum format.
dp_python_lib-<version>-py3-none-any.whl.sigstore.json
dp_python_lib-<version>.tar.gz.sigstore.json
SHA256SUMS.sigstore.json
Keyless Sigstore signature bundles, one per file above.
Releases before rel-1.16.0 may lack SHA256SUMS or the Sigstore bundles; the
verification steps below do not apply to them.
------------------------------------------------------------
Download and Installation
------------------------------------------------------------
1. Download the artifacts from the GitHub Release page into a single directory,
with no subdirectories. Both commands below expect to find the files side
by side. With the GitHub CLI:
gh release download rel-<version> -R osprey-dcs/dp-python-lib
2. Verify the checksums:
sha256sum -c SHA256SUMS
(On macOS without GNU coreutils: shasum -a 256 -c SHA256SUMS)
The output should indicate:
dp_python_lib-<version>-py3-none-any.whl: OK
dp_python_lib-<version>.tar.gz: OK
SHA256SUMS lists both distributions, so this fails if you downloaded only
the wheel. To check the files you actually have and ignore the rest:
sha256sum --ignore-missing -c SHA256SUMS
Note that --ignore-missing succeeds if it checked nothing at all, so confirm
the file you care about is listed as OK rather than relying on the exit code.
3. Verify the signatures.
The checksums establish integrity but not origin: they are published to the
same release page as the artifacts, so anyone able to replace a file could
replace its checksum alongside it. The Sigstore signatures close that gap by
binding each file to the repository, workflow file, and tag that produced
it. There is no public key to fetch or trust: the signing identity is a
short-lived certificate issued to the GitHub Actions run and recorded in the
public Rekor transparency log.
Install the Sigstore client:
pip install sigstore
Then, substituting the release's tag in both places:
sigstore verify identity \
--cert-identity "https://github.com/osprey-dcs/dp-python-lib/.github/workflows/release.yml@refs/tags/rel-<version>" \
--cert-oidc-issuer "https://token.actions.githubusercontent.com" \
dp_python_lib-*.whl dp_python_lib-*.tar.gz SHA256SUMS
Each file's bundle is found automatically as <file>.sigstore.json. The
output should be one line per file:
OK: dp_python_lib-<version>-py3-none-any.whl
OK: dp_python_lib-<version>.tar.gz
OK: SHA256SUMS
The --cert-identity is an exact match, pinned to this repository, this
workflow file, and one tag. A signature made by any other workflow, any
other repository, or the run for a different tag fails with
"Certificate's SANs do not match". Do not loosen it to make a failure go
away; a mismatch is the check doing its job.
4. Install the wheel:
pip install dp_python_lib-<version>-py3-none-any.whl
Optional extras are installed the usual way, e.g.:
pip install "dp_python_lib-<version>-py3-none-any.whl[analysis]"
------------------------------------------------------------
Release Notes
------------------------------------------------------------
The body of each GitHub Release is the version-controlled file
doc/release-notes/rel-<version>.md, published verbatim. Each carries a short
"Verifying these artifacts" section with that release's exact identity; this
file is the fuller reference it points to.
------------------------------------------------------------
Notes
------------------------------------------------------------
- dp-python-lib is a client library; it does not run as a standalone service.
- It talks to the MLDP services implemented in dp-service, over the gRPC API
defined in dp-grpc.
- Publishing to PyPI is not enabled yet; GitHub Releases are the distribution
channel.