agriyakhetarpal/hugo-python-distributions

Security

agriyakhetarpal opened this issue · 1 comments

  • Security disclaimers in the documentation
  • GPG-sign binaries (or use sigstore) when publishing to PyPI
  • Add some guidelines for users for verifiability of downloaded wheels

See #70.

Additional: look into security policies for Hugo, Chocolatey, Homebrew, MacPorts, and finally, pip