Are We PEP740 Yet?

PEP 740 is a Python standard for cryptographically verifiable attestations on PyPI. Attestations are signed statements about Python packages, adding security by using short-lived keys. The site displays the top 360 PyPI packages, showing which have attestations. Green packages are verified, uncolored lack attestations, and yellow have none yet. To add attestations, use a Trusted Publisher or upgrade to the latest PyPA publishing action. Report any issues or contribute to improving the site. This project is derived from Free-Threaded Wheels and Python Wheels, with thanks to contributors. Remember to enable JavaScript on pythonwheels.com for the full package list.

https://trailofbits.github.io/are-we-pep740-yet/

To top