生成证明
PyPI 允许在上传时将证明附加到各个发布文件(发布版本中的源代码和二进制分发包)。
先决条件
在将证明文件上传至索引之前,请:
- 请查看Linux 基金会的《不可变记录》通知,该通知适用于公共透明度日志。
-
使用受支持的 CI/CD 提供商设置可信发布。下方列出了受支持的提供商及其各自的设置说明。
笔记
我们计划支持其他受信任的发布者。更多信息请参见#17001 。
生成证明
最简单的方法
如果您使用pypa/gh-action-pypi-publish
(官方 PyPA 操作)发布到 PyPI,默认情况下会自动生成并上传证明,无需额外配置。
手动方式
警告
注意!您可能不需要阅读此部分;它仅用于提供一些关于认证生成和上传的内部细节。如果您是普通用户,强烈建议您使用上述官方工作流程之一。
生成证明
重要的
手动生成认证并不能绕过 PyPI 目前对受支持的认证身份(即受信任的发布者)的限制。以下示例可用于使用受信任的发布者或 其他身份进行签名,但 PyPI 会在上传时拒绝非受信任发布者的认证。
使用pypi-attestations
pypi-attestations是一个便捷的库和命令行界面 (CLI),用于生成和操作证明对象。您可以使用任一接口来生成证明。
例如,要为所有分布生成证明dist/:
python -m pip install pypi-attestations
python -m pypi_attestations sign dist/*
如果上述操作在启用了可信发布功能的 GitHub Actions 工作流中运行id-token: write
(即,可信发布的普通上下文),它将使用调用它的 GitHub Actions 工作流的环境身份。
如果在本地运行,它会提示您执行 OAuth 流程以建立身份,并使用生成的身份。
有关作为 Python 库的使用方法,请参阅pypi-attestations 的文档。
从 Sigstore 捆绑包转换
证明在功能上(但不在结构上)与Sigstore 包兼容 ,这意味着任何可以生成 Sigstore 包的系统都可以进行调整以生成证明。
例如,GitHubactions/attest可以用于生成带有 PyPI发布证明标记的 Sigstore 包:
- name: attest
uses: actions/attest@v1
with:
# Attest to every distribution
subject-path: dist/*
predicate-type: 'https://pypi.com.cn/attestations/publish/v1'
predicate: '{}'
sigstore-python生成后,每个 Sigstore 包都可以在同一工作流程中或离线使用以下API 转换为等效的认证pypi-attestation:
from pypi_attestations import Attestation
from sigstore.models import Bundle
raw_bundle = "..." # read the bundle's JSON
bundle = Bundle.from_json(raw_bundle)
attestation = Attestation.from_bundle(bundle)
print(attestation.model_dump_json())
上传证明文件
认证文件会作为正常文件上传流程的一部分上传到 PyPI。
如果您正在使用twine,可以通过向以下参数传递信息来上传任何相邻的证明及其关联--attestations文件twine upload:
twine upload --attestations dist/*
请参阅 PyPI 的旧版上传 API 文档,了解如何在上传 API 级别向文件上传添加证明。
首先,应该已经设置好使用可信发布进行上传的 GitLab 工作流。请参阅此处的说明。
一旦该工作流程建立起来,就可以通过在工作流程中添加一个在构建之后、发布之前运行的额外作业来生成证明:
generate-pypi-attestations:
stage: build
image: python:3-bookworm
needs:
- job: build-job
artifacts: true
id_tokens:
SIGSTORE_ID_TOKEN:
aud: sigstore
script:
- python -m pip install -U pypi-attestations
- python -m pypi_attestations sign python_pkg/dist/*
artifacts:
paths:
- "python_pkg/dist/"
整个工作流程,包括三个任务(构建、生成证明和发布),如下所示:
build-job:
stage: build
image: python:3-bookworm
script:
- python -m pip install -U build
- cd python_pkg && python -m build
artifacts:
paths:
- "python_pkg/dist/"
generate-pypi-attestations:
stage: build
image: python:3-bookworm
needs:
- job: build-job
artifacts: true
id_tokens:
SIGSTORE_ID_TOKEN:
aud: sigstore
script:
- python -m pip install -U pypi-attestations
- python -m pypi_attestations sign python_pkg/dist/*
artifacts:
paths:
- "python_pkg/dist/"
publish-job:
stage: deploy
image: python:3-bookworm
dependencies:
- build-job
- generate-pypi-attestations
id_tokens:
PYPI_ID_TOKEN:
# Use "testpypi" if uploading to TestPyPI
aud: pypi
script:
# Install dependencies
- python -m pip install -U twine
# Upload to PyPI using Trusted Publishing, including the generated attestations
# Add "--repository testpypi" if uploading to TestPyPI
- twine upload --attestations python_pkg/dist/*
请注意,与可信发布工作流程相比,它有以下变化:
- 新增了一项任务,用于
generate-pypi-attestations生成证明并将其存储为工件。 - 发布作业现在也依赖于
generate-pypi-attestations,因为它需要从中下载生成的证明。 - 发布作业现在会调用
twine传递--attestations标志的函数,以启用证明上传。
pypi-attestations是一个便捷的库和命令行界面 (CLI),用于生成和操作证明对象。您可以使用任一接口来生成证明。
例如,要为所有分布生成证明dist/:
python -m pip install pypi-attestations
python -m pypi_attestations sign dist/*
如果上述操作在具有工作负载标识的 Google Cloud 服务 (例如 Cloud Build、Compute Engine 等)中运行,则它将使用调用它的服务的环境标识。
有关作为 Python 库的使用方法,请参阅pypi-attestations 的文档。