What to build
Give the non-PyPI release artifacts the provenance the PyPI lane gets from PEP 740. There's no index-side attestation story for .c4z or the HACS GitHub release, so attach SLSA build provenance (actions/attest-build-provenance) and publish a checksum for the .c4z artifact, letting consumers verify it was built by this repo's workflow. Evaluate doing the same for the HACS release.
Acceptance criteria
Blocked by
None - can start immediately
What to build
Give the non-PyPI release artifacts the provenance the PyPI lane gets from PEP 740. There's no index-side attestation story for
.c4zor the HACS GitHub release, so attach SLSA build provenance (actions/attest-build-provenance) and publish a checksum for the.c4zartifact, letting consumers verify it was built by this repo's workflow. Evaluate doing the same for the HACS release.Acceptance criteria
.c4zrelease publishes a SLSA build-provenance attestation and a checksumBlocked by
None - can start immediately