in the name of supply chain security, i just want verified package signatures (cosign, not the extant unused gpg), the new passwordless publication is good step towards (get humans and static credentials out of pushing assets). actually one more minor, support for poetry in pip-audit.. <a href="https://github.com/pypa/pip-audit/issues/84">https://github.com/pypa/pip-audit/issues/84</a>