-
Notifications
You must be signed in to change notification settings - Fork 0
Closed
Description
Cross reference with https://discuss.scientific-python.org/t/spec-8-supply-chain-security/1163
Copying from @tupui's original post there, areas of focus could be:
- OpenSSF 4 has a scorecard system and I think it would be good to follow their recommendations. They also provide scorecards 2 with interesting metrics.
- Trusted Publishers: GitHub to PyPi
- SLSA 5, secure artifacts. It’s easy to do with GH actions, e.g. with Flask
- Build on top of SPEC 6 (keys to the castle)
tupui, jarrodmillman and agriyakhetarpal
Metadata
Metadata
Labels
No labels
Type
Projects
Status
Done