Hacker News new | ask | show | jobs
by someguydave 76 days ago
apparently PyPI supports "digital attestation" (signed binaries?) Was this package signed? https://docs.pypi.org/trusted-publishers/