Skip to content

Conversation

wolfv
Copy link
Contributor

@wolfv wolfv commented Sep 18, 2025

This integrates cosign into the rattler_upload.

Using cosign we can generate sigstore attestations on the fly with the exact format (predicate) that the prefix server / conda ecosystem expects. It makes the flow super smooth. Cosign also integrates into Github.

@baszalmstra
Copy link
Collaborator

Can you update this PR?

@wolfv
Copy link
Contributor Author

wolfv commented Oct 12, 2025

I removed unrelated changes into a separate PR here: #1727

Will improve the remaining changes in here some more :)

@wolfv
Copy link
Contributor Author

wolfv commented Oct 12, 2025

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants