Conversation
|
Just to be sure: as per docs the cache: 'pip'seems to cache Furthermore, note that SLSA Build Level 3 requires to
The term “run” isn’t clearly defined, but we need to keep in mind that while the public PyPI artifactory is trusted, caches in between are not because modifications/tempering is invisible to us (see also cache poisoning). (And that includes an AWS Artifactory or the like!) Also, looking at the runtimes of the So, do we have a measurable impact resulting from this? |
|
@behnazh what do you think of this comment: pre-commit/pre-commit#2847 (comment) |
This solution seems to have similar issues for build isolation. We have designed |

Add pip cache to Setup python step