Description
pypa/gh-action-pypi-publish already used for OIDC trusted publishing. Adding attestations: true emits Sigstore-backed wheel attestations visible on PyPI. Same credibility tier as npm provenance already in place on TS SDK.
Acceptance criteria
Description
pypa/gh-action-pypi-publishalready used for OIDC trusted publishing. Addingattestations: trueemits Sigstore-backed wheel attestations visible on PyPI. Same credibility tier as npm provenance already in place on TS SDK.Acceptance criteria
attestations: truein publish step