Is there any effort to integrate SLSA with PyPI? GitHub recently announced[1] that npm support for SLSA is GA now.
[1] https://github.blog/changelog/2023-09-26-npm-provenance-gene...
[1] https://github.blog/changelog/2023-09-26-npm-provenance-gene...
[1] https://docs.pypi.org/trusted-publishers/
[2] https://github.com/ossf/wg-securing-software-https://docs.py...
I don't think there's a big effort /right now/ to implement complete SLSA build provenance for PyPI and expose it for users to verify.