Great, now how do you use attestations with Twine when publishing packages on PyPI outside of the Github ecosystem?
And of course the signature means "this user can push to github" and nothing more.
Otherwise I don't get it.
But my CI can download and run code from everywhere, so that doesn't mean that I can know what is being uploaded just looking at the git repository alone.