Closed steiza closed 1 year ago
It'd be nice to publish https://github.com/ossf/wg-securing-software-repos/blob/main/docs/build-provenance-for-all-package-registries.md as a *.openssf.org webpage.
There's a process for doing so: https://best.openssf.org/spp/Simplest-Possible-Process
In particular, an admin of this repository needs to go through https://best.openssf.org/spp/Simplest-Possible-Process#one-time-setup
I believe this is done - see https://repos.openssf.org/proposals/build-provenance-and-code-signing-for-homebrew and https://repos.openssf.org/build-provenance-for-all-package-registries
One last thing we should do is put something at the index, because https://repos.openssf.org/ is currently 404.
It'd be nice to publish https://github.com/ossf/wg-securing-software-repos/blob/main/docs/build-provenance-for-all-package-registries.md as a *.openssf.org webpage.
There's a process for doing so: https://best.openssf.org/spp/Simplest-Possible-Process
In particular, an admin of this repository needs to go through https://best.openssf.org/spp/Simplest-Possible-Process#one-time-setup