-
Notifications
You must be signed in to change notification settings - Fork 0
Open
Labels
Description
Might be worth exploring in future as part of the release process - generating SBOM and attestations: https://docs.github.com/en/actions/how-tos/secure-your-work/use-artifact-attestations/use-artifact-attestations#generating-an-attestation-for-a-software-bill-of-materials-sbom
NOTE: we currently generate attestations for the release artifacts (sdist + wheel)