Issues
- 3
Add recommednations for package repositories looking to rollout Trusted Publishers
#45 opened by sethmlarson - 0
- 1
With "trusted publishers" is there any user-verifiable evidence that a particular pypi package is based on a particular CI workflow?
#46 opened by nealmcb - 0
- 2
Document recent security capabilities of package repositories, and their funding source
#39 opened by steiza - 2
Brainstorm ideas on how to improve "Principles for Package Repository Security" from CISA OSS Summit
#40 opened by david-a-wheeler - 2
The Great Artifact Repository Security Audit
#14 opened by JLLeitschuh - 8
- 2
- 1
- 5
- 12
- 2