Skip to content

Request: signed checksum and keyring provenance for Python 3.13.5 embeddable package #154935

Description

@neyasiikea

We are preparing a reproducible offline Windows runtime package and need artifact-bound provenance for the official Python embeddable package.

Target release:

  • tag: v3.13.5
  • artifact: python-3.13.5-embed-amd64.zip

Could the project publish or document the following for this exact artifact?

  1. A signed SHA-256 checksum subject that explicitly covers the ZIP.
  2. A detached signature for that checksum subject or the ZIP.
  3. An independently verifiable official Python release keyring URL.
  4. The signer fingerprint and exact signature coverage.
  5. Artifact-bound LICENSE/NOTICE/third-party evidence.
  6. A complete embedded Python/Hermes dependency and wheel URL/hash closure.

The release metadata JSON and a key ID alone are not sufficient to establish signed checksum coverage or official keyring provenance.

Please publish the material as official release assets or official Python release documentation if possible.

Metadata

Metadata

Assignees

No one assigned

    Labels

    pendingThe issue will be closed if no feedback is provided

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions