While discussing Issue #9, it was brought up that we should try to add Trusted Publishers, SLSA signing to reporeview and then also look at the OpenSSF scorecards to see if there are things we care about there that maybe could be brought over (example, limiting GitHub Action runner privilges by default (c.f. scikit-hep/pyhf#2483)).
Assigning @henryiii given interest, not to say that he is responsible for all changes.
Tagging @jarrodmillman, @stefanv, @juanis2112 given other comments.
While discussing Issue #9, it was brought up that we should try to add Trusted Publishers, SLSA signing to reporeview and then also look at the OpenSSF scorecards to see if there are things we care about there that maybe could be brought over (example, limiting GitHub Action runner privilges by default (c.f. scikit-hep/pyhf#2483)).
Assigning @henryiii given interest, not to say that he is responsible for all changes.
Tagging @jarrodmillman, @stefanv, @juanis2112 given other comments.