Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

Make artifact verification instructions more visible #2463

Copy link
Copy link
Open
@sethmlarson

Description

@sethmlarson
Issue body actions

Today our download pages allude to being able to verify artifacts, either through Sigstore (recommended) or GPG, however these instructions aren't as clearly documented as they could be and in theory we want everyone downloading from python.org to be taking advantage of one of these two options.

My proposal is to:

  • Add an anchor to the download details page for GPG identities so it can be linked to directly.
  • For all download detail pages:
    • Provide a link to the instructions for verifying with GPG
    • If there are Sigstore artifacts, also provide links to instructions for verifying Sigstore.
    • Recommend users using Sigstore over GPG when it's available.

Metadata

Metadata

Assignees

No one assigned

    Labels

    adminRelates to Django AdminRelates to Django Adminapp/downloadsRelates to the downloads appRelates to the downloads appbackendRelates to the backend of the appRelates to the backend of the appfrontendRelates to the frontend of the appRelates to the frontend of the app

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions

      Morty Proxy This is a proxified and sanitized view of the page, visit original site.