-
Notifications
You must be signed in to change notification settings - Fork 545
Open
Description
I'm surprised nobody talked about PyPI Trusted Publisher on this important security-related library.
I know this can't solve all the problem, but with increasing supply chain attack, trusted publisher could possibly mitigate part of the attack vector.
I'm not sure what the reason is behind it. Is there concerns I'm not aware of, or just no manpower to do it
If it's just manpower issue, I'm happy to contribute
EpicWink
Metadata
Metadata
Assignees
Labels
No labels