We are preparing a reproducible offline Windows runtime package and need artifact-bound provenance for the official Python embeddable package.
Target release:
- tag: v3.13.5
- artifact: python-3.13.5-embed-amd64.zip
Could the project publish or document the following for this exact artifact?
- A signed SHA-256 checksum subject that explicitly covers the ZIP.
- A detached signature for that checksum subject or the ZIP.
- An independently verifiable official Python release keyring URL.
- The signer fingerprint and exact signature coverage.
- Artifact-bound LICENSE/NOTICE/third-party evidence.
- A complete embedded Python/Hermes dependency and wheel URL/hash closure.
The release metadata JSON and a key ID alone are not sufficient to establish signed checksum coverage or official keyring provenance.
Please publish the material as official release assets or official Python release documentation if possible.
We are preparing a reproducible offline Windows runtime package and need artifact-bound provenance for the official Python embeddable package.
Target release:
Could the project publish or document the following for this exact artifact?
The release metadata JSON and a key ID alone are not sufficient to establish signed checksum coverage or official keyring provenance.
Please publish the material as official release assets or official Python release documentation if possible.