GeistHaus
log in · sign up

Are we PEP 740 yet? 🔏

trailofbits.github.io
5 pages link to this URL
Attestations: A new generation of signatures on PyPI

For the past year, we’ve worked with the Python Package Index (PyPI) on a new security feature for the Python ecosystem: index-hosted digital attestations, as specified in PEP 740. These attestations improve on traditional PGP signatures (which have been disabled on PyPI) by providing key usability, index verifiability, cryptographic strength, and provenance properties that bring […]

1 inbound link article en open-sourcesupply-chainecosystem-securityengineering-practice open-sourcesupply-chainecosystem-securityengineering-practice
Attestations: A new generation of signatures on PyPI

For the past year, we’ve worked with the Python Package Index (PyPI) on a new security feature for the Python ecosystem: index-hosted digital attestations, as specified in PEP 740. These attestations improve on traditional PGP signatures (which have been disabled on PyPI) by providing key usability, index verifiability, cryptographic strength, and provenance properties that bring […]

3 inbound links article en open-sourcesupply-chainecosystem-securityengineering-practice open-sourcesupply-chainecosystem-securityengineering-practice
Defense in Depth: A Practical Guide to Python Supply Chain Security

A comprehensive guide to securing your Python dependencies from ingestion to deployment, covering linting, pinning, vulnerability scanning, SBOMs, and attestations

6 inbound links article en posts pythonsecuritydependenciessupply-chainsbompypipip