Cross reference with https://discuss.scientific-python.org/t/spec-8-supply-chain-security/1163
Copying from @tupui's original post there, areas of focus could be:
- OpenSSF 4 has a scorecard system and I think it would be good to follow their recommendations. They also provide scorecards 2 with interesting metrics.
- Trusted Publishers: GitHub to PyPi
- SLSA 5, secure artifacts. It’s easy to do with GH actions, e.g. with Flask
- Build on top of SPEC 6 (keys to the castle)
Cross reference with https://discuss.scientific-python.org/t/spec-8-supply-chain-security/1163
Copying from @tupui's original post there, areas of focus could be: