Artifact Integrity and Release Verification¶
SpindleX releases should provide enough evidence for maintainers and users to verify what was published.
Integrity Signals¶
The release process should provide:
- wheel and sdist built from the release commit
twine checkoutput- wheel import/version validation
- PyPI install verification
- annotated Git tag
- release notes linked to changelog
- SHA-256 hashes for release artifacts
- SBOM artifact where tooling is practical
- GitHub artifact attestations when available
User Verification¶
Users can verify a release by:
- Installing an exact version, for example
spindlex==0.7.0. - Checking
python -c "import spindlex; print(spindlex.__version__)". - Comparing wheel or sdist hashes from the GitHub Release when published.
- Reviewing the tag and release notes.
Maintainer Policy¶
SBOM, hash, and attestation generation may run as non-blocking steps. Maintainers decide which integrity failures block a release and update this page when that policy changes.
PyPI trusted publishing should remain the preferred publishing path. Long-lived PyPI tokens should not be required for the normal release process.