Security

Distributors are recommended to fetch release sources via the Git tags on our repository, or the source distributions on the meson-python PyPI page, both are PGP-signed with one of the following keys:

Fetching artifact signatures from PyPI

To fetch the PGP signatures for artifacts on PyPI, simply add .asc to the artifact URL.