alire-project / alire

Command-line tool from the Alire project and supporting library
GNU General Public License v3.0
288 stars 49 forks source link

Mitigations against supply-chain attacks #991

Open mosteo opened 2 years ago

mosteo commented 2 years ago

This is likely a long-term wish, but so it not gets entirely forgotten.

See https://go.dev/blog/supply-chain

Some ideas:

JeremyGrosser commented 2 years ago

The OpenSSF organization has some good guidelines around supply chain security documented here: https://github.com/ossf/wg-best-practices-os-developers