Skip to main content

gcp-attest

Produce Digital Attestations and use PyPI Trusted Publishing using Google Cloud service accounts.

Why

PyPI encourages Trusted Publishing, but their supported platforms do not include Codeberg. This is understandable: Supporting a new platform means trusting it, and for a long time neither of Codeberg's CI options even had an option to issue OIDC tokens.

PyPI trusts Google's OIDC, though. All OIDC tokens issued by Google Cloud IAM can be exchanged against valid PyPI publishing tokens. The same applies to Sigstore and digital attestations.

Google Cloud OIDC tokens usually represent a service account. There are multiple ways to "log in" as said account to issue tokens:

  1. Inside a Google Cloud workflow. This is the expected way and already supported by di/id and pypi-attestations.
  2. Using a long-lived credentials key file.
  3. Using Workload Identity Federation

The last one is interesting, as it allows us to exchange OIDC tokens from any valid identity provider for Google Cloud tokens. This way, Google Cloud acts like a proxy between PyPI and not (yet) supported OIDC providers.

This project aims to simplify publishing process by offering APIs to create attestations and exchange tokens.

Licence

© 2026 Nikita Karamov
Licensed under the ISC License

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

gcp_attest-0.3.0.tar.gz (155.2 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

gcp_attest-0.3.0-py3-none-any.whl (7.8 kB view details)

Uploaded Python 3

File details

Details for the file gcp_attest-0.3.0.tar.gz.

File metadata

  • Download URL: gcp_attest-0.3.0.tar.gz
  • Upload date:
  • Size: 155.2 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.2.0 CPython/3.14.6

File hashes

Hashes for gcp_attest-0.3.0.tar.gz
Algorithm Hash digest
SHA256 e9dd4a6859461e9ff0e87db418cdd848447318a6add1a9f0b840619963f0f422
MD5 eeb5a35d6d5c20e07232142530f50044
BLAKE2b-256 ceec0d1a605a9637c4fef413253f69912bc498b7c0df3d22e17a63e8801ada52

See more details on using hashes here.

Provenance

The following attestation bundles were made for gcp_attest-0.3.0.tar.gz:

Publisher: pypi-publish@kytta-dev.iam.gserviceaccount.com

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.
  • Statement: Publication detail:
    • Token Issuer: https://accounts.google.com
    • Service Account: pypi-publish@kytta-dev.iam.gserviceaccount.com

File details

Details for the file gcp_attest-0.3.0-py3-none-any.whl.

File metadata

  • Download URL: gcp_attest-0.3.0-py3-none-any.whl
  • Upload date:
  • Size: 7.8 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.2.0 CPython/3.14.6

File hashes

Hashes for gcp_attest-0.3.0-py3-none-any.whl
Algorithm Hash digest
SHA256 3dd998166cf6b95160943d74822ea7deaa0030157fe263df3774a192cde1d884
MD5 0dbf69a6b2716a7d45b1c972d782d7a7
BLAKE2b-256 8cd8514f015cc614ed5802755903d51a40d2d6482cebc4e562e6602c40673ea3

See more details on using hashes here.

Provenance

The following attestation bundles were made for gcp_attest-0.3.0-py3-none-any.whl:

Publisher: pypi-publish@kytta-dev.iam.gserviceaccount.com

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.
  • Statement: Publication detail:
    • Token Issuer: https://accounts.google.com
    • Service Account: pypi-publish@kytta-dev.iam.gserviceaccount.com

Release history Release notifications | RSS feed

0.3.1.post1

2 files

0.3.1

2 files

This release

0.3.0 This release

2 files

0.2.0

2 files

0.1.0

2 files

0.0.1

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page