CISA highly encourages package managers and open source community members to review the Principles for Package Repository Security as well as the related OpenSSF blog post, offer feedback, and develop ...
The OpenSSF is releasing a new framework that can be used to assess the security capabilities of package repositories and help plan for future improvements. Called the Principles for Package ...