This working group has produced a ton of useful information about how best to build a secure package repository, along with data on what repositories are currently doing. Can we crystallize this into an easy-to-digest guide to package repository security for package repository admins/maintainers? Topics would include (by no means complete):
(There could also be a good research paper "Systematization of Knowledge" here—CC @joshuagl).
CC @woodruffw
Misc references
This working group has produced a ton of useful information about how best to build a secure package repository, along with data on what repositories are currently doing. Can we crystallize this into an easy-to-digest guide to package repository security for package repository admins/maintainers? Topics would include (by no means complete):
(There could also be a good research paper "Systematization of Knowledge" here—CC @joshuagl).
CC @woodruffw
Misc references