Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

pylock attestations

CI PyPI version Packaging status

CLI tool to add attestation identities to a pylock.toml file.

[!IMPORTANT] This CLI is currently in alpha and not ready for production use.

Installation

Install using uv or pipx:

# with uv:
uv tool install pylock-attestations

# with pipx:
pipx install pylock-attestations

Usage

Run the pylock-attestations command inside a project folder containing a pylock.toml file to update it in-place:

cd my_project/

pylock-attestations

You can also specify the input and output files:

cd my_project/

pylock-attestations -i pylock.old.toml -o pylock.new.toml

License

Copyright 2025 Trail of Bits

Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.

You may obtain a copy of the License at
    http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.

Metadata

Release files for pylock-attestations 0.0.1a2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for pylock-attestations 0.0.1a2
File Size Uploaded
pylock_attestations-0.0.1a2.tar.gz 67.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for pylock-attestations 0.0.1a2
File Interpreter ABI Platform
pylock_attestations-0.0.1a2-py3-none-any.whl Python 3 none any Details

Total release size: 140.7 kB

Release files / pylock_attestations-0.0.1a2.tar.gz

Download URL pylock_attestations-0.0.1a2.tar.gz
Size 67.3 kB
Tags Source
SHA-256 checksum
How to use checksums
e678e23a6a7bc04d16b6bf85ec20cf0abd39e1b502d71717393fd2249128cfe5
BLAKE2b-256 checksum
How to use checksums
12e135574b16c9620716ba9bfb8282b60b9b3f103ef5887c11fe6a1fcfa6cab8
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.12.9

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on May 14, 2025.

Transparency log

Release files / pylock_attestations-0.0.1a2-py3-none-any.whl

Download URL pylock_attestations-0.0.1a2-py3-none-any.whl
Size 73.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
3c52894e302d4e542a0a091534da73f78fe36bab1a3359278644dbe1ee29692e
BLAKE2b-256 checksum
How to use checksums
a94a91bd10052a3e6cf8c3087db3c0536ea6570c4ccc9948d624be211dea9f6a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.12.9

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on May 14, 2025.

Transparency log

Release history Release notifications | RSS feed

This release

0.0.1a2 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page