microsoft / scitt-ccf-ledger

Supply Chain Integrity Transparency and Trust ledger application using Confidential Consortium Framework (CCF)
MIT License
35 stars 16 forks source link

Azure DevOps to use private feeds for Python deps #221

Closed ivarprudnikov closed 2 months ago

ivarprudnikov commented 2 months ago

Consume Python dependencies though the internal feeds as opposed to public ones when building PRs in Azure DevOps pipelines. This should solve governance alerts but it does not really change the way dependencies are ingested in the case when publishing to pypi.