Can someone confirm for me using a non robot answer that to have package attestations on pypi, your entire build process and upload must entirely take place using a commercial CI provider such as GitHub actions. It will never be possible to do the actual build on your local machine anymore and twine is effectively a thing of the past if you want your packages to be trusted. This is what I'm being told
Replying to @zzzeek@hachyderm.io
right as I'm preparing to work up a comprehensive migration of my whole release architecture across six projects to use github actions, because I care about supply chain attacks and pep-740 compliance currently requires one of a very small list of trusted hosts
— Open image attachment 1 of 1screenshot from github
Incident with Actions and Pages
Subscribe
Update - We are investigating authentication issues leading to failure in starting Actions runs and downloading actions. At this time the majority of Actions runs is impacted.
May 26, 2026 - 11:53 UTC
Update - Actions is experiencing degraded availability. We are continuing to investigate.
May 26, 2026 - 11:19 UTC
Investigating - We are investigating reports of degraded performance for Actions and Pages
May 26, 2026 - 10:57 UTC
