Open Source Security
PyPI Attestation Requirements: A Roadmap Read
PEP 740 brings Sigstore-style attestations to PyPI. A close read of the roadmap, what's actually shipped, and what it means for consumers and publishers over the next 12 months.
Mar 10, 20257 min read