Skip to content

docs: VERIFY.md records the 0.12.0 verification - #85

Merged
philpaz merged 1 commit into
mainfrom
docs/verify-0.12.0
Oct 10, 2026
Merged

philpaz merged 1 commit into
mainfrom
docs/verify-0.12.0

Conversation

@philpaz

@philpaz philpaz commented Oct 10, 2026

Copy link
Copy Markdown
Owner

Records the verification of the published 0.12.0, as #66 did for 0.11.1.

  • verify-release run 38084175026: build provenance and the Sigstore signatures of the wheel and sdist verified; both negative controls refused (a signer workflow that never built, an identity that never signed).
  • PyPI serves bytes identical to the release assets, each with PEP 740 provenance naming philpaz/recusal and release.yml.
  • Fresh pip install recusal==0.12.0 on Python 3.9 and 3.12: reports 0.12.0, the allowlist predicate refuses Read, decide(audit=) records one entry, a surface without a log raises, and a NaN input is denied when recorded.

Command examples on the page now use 0.12.0.

verify-release run 38084175026 against the published 0.12.0: build provenance and Sigstore signatures verified, both negative controls refused, PyPI bytes match the release assets with PEP 740 provenance naming release.yml. Command examples now use 0.12.0.
@philpaz
philpaz merged commit 2611f2e into main Oct 10, 2026
18 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant