Open schlenk opened 9 months ago
It would be nice to use the SLSA framework to get provenance assertions for the release packages we put on PyPi.
See: https://sethmlarson.dev/python-and-slsa
No objections :)
It would be nice to use the SLSA framework to get provenance assertions for the release packages we put on PyPi.
See: https://sethmlarson.dev/python-and-slsa