Skip to content

GPG signing builds? #543

Answered by firecat53
firecat53 asked this question in Q&A
Oct 10, 2022 · 4 comments · 1 reply
Discussion options

You must be logged in to vote

After a little reading, I discovered that apparently GPG python package signing is not really a thing. Pypi doesn't present the GPG signature other than through their API. There's nothing visible on the Pypi website. Other tools such as Poetry also do not incorporate GPG signatures. So I guess unless something changes with Pypi, it's a non-issue. I've been signing my packages for years and never really looked to see if it meant anything! 🤷

Replies: 4 comments 1 reply

Comment options

ofek
Oct 10, 2022
Maintainer Sponsor

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
1 reply
@ofek
Comment options

ofek Oct 12, 2022
Maintainer Sponsor

Answer selected by firecat53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants