Skip to main content

gcp-attest

Produce Digital Attestations and use PyPI Trusted Publishing using Google Cloud service accounts.

Why

PyPI encourages Trusted Publishing, but their supported platforms do not include Codeberg. This is understandable: Supporting a new platform means trusting it, and for a long time neither of Codeberg's CI options even had an option to issue OIDC tokens.

PyPI trusts Google's OIDC, though. All OIDC tokens issued by Google Cloud IAM can be exchanged against valid PyPI publishing tokens. The same applies to Sigstore and digital attestations.

Google Cloud OIDC tokens usually represent a service account. There are multiple ways to "log in" as said account to issue tokens:

  1. Inside a Google Cloud workflow. This is the expected way and already supported by di/id and pypi-attestations.
  2. Using a long-lived credentials key file.
  3. Using Workload Identity Federation

The last one is interesting, as it allows us to exchange OIDC tokens from any valid identity provider for Google Cloud tokens. This way, Google Cloud acts like a proxy between PyPI and not (yet) supported OIDC providers.

This project aims to simplify publishing process by offering APIs to create attestations and exchange tokens.

Licence

© 2026 Nikita Karamov
Licensed under the ISC License

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

gcp_attest-0.3.1.tar.gz (155.2 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

gcp_attest-0.3.1-py3-none-any.whl (7.8 kB view details)

Uploaded Python 3

File details

Details for the file gcp_attest-0.3.1.tar.gz.

File metadata

  • Download URL: gcp_attest-0.3.1.tar.gz
  • Upload date:
  • Size: 155.2 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.2.0 CPython/3.14.6

File hashes

Hashes for gcp_attest-0.3.1.tar.gz
Algorithm Hash digest
SHA256 5afa62a2575d5282612c7019108d450abf6a38d9bc82e110323a2528e6dedc17
MD5 8ea4c074a9f639999bee7dd2803ba5cc
BLAKE2b-256 27fd00f75a1d78450e941b79541a13e95090740004bd69ba3ea370c472dd117a

See more details on using hashes here.

Provenance

The following attestation bundles were made for gcp_attest-0.3.1.tar.gz:

Publisher: pypi-publish@kytta-dev.iam.gserviceaccount.com

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.
  • Statement: Publication detail:
    • Token Issuer: https://accounts.google.com
    • Service Account: pypi-publish@kytta-dev.iam.gserviceaccount.com

File details

Details for the file gcp_attest-0.3.1-py3-none-any.whl.

File metadata

  • Download URL: gcp_attest-0.3.1-py3-none-any.whl
  • Upload date:
  • Size: 7.8 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.2.0 CPython/3.14.6

File hashes

Hashes for gcp_attest-0.3.1-py3-none-any.whl
Algorithm Hash digest
SHA256 0caf46d174e92158d7861fe7aa6d22d34a8b7cb6b058dd44a23a0a9b34e0f278
MD5 db15a68783d04253f2ba1dc67637df34
BLAKE2b-256 dff0d39c77d70d1e681adeb39597c78023e168abd9d6c7deaac2251f25cdf25f

See more details on using hashes here.

Provenance

The following attestation bundles were made for gcp_attest-0.3.1-py3-none-any.whl:

Publisher: pypi-publish@kytta-dev.iam.gserviceaccount.com

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.
  • Statement: Publication detail:
    • Token Issuer: https://accounts.google.com
    • Service Account: pypi-publish@kytta-dev.iam.gserviceaccount.com

Release history Release notifications | RSS feed

0.3.1.post1

2 files

This release

0.3.1 This release

2 files

0.3.0

2 files

0.2.0

2 files

0.1.0

2 files

0.0.1

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page