Skip to content

Record attestations #1276

@andrew

Description

@andrew

note: This is a bit of a placeholder issue right now as I need to do more research in this space.

Multiple package managers now support trusted publishing and are generating attestations and making them available via APIs, we can record them against packages/versions.

There's also attestations in GitHub and GitLab at a repository level that we can store too, which will be a feature in https://github.com/ecosyste-ms/repos/

Will expand on this issue soon.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions