intersystems / intersystems/ipm
Signed and Verifiable Packages
Open
enhancement
prio: medium
- Dominant language
- ObjectScript
- Stars
- 41
- Forks
- 29
- Avg merge
- 23h 54m
- Merged PRs (30d)
- 4
Description
It is absolutely critical that we have clear and verifiable sightlines into the source code supply chains. Software supply chain is one of the most common attack vectors for hackers. Here's a little overview of the topic: https://blog.tidelift.com/the-state-of-package-signing-across-package-managers
ZPM packages should be signed by their authors and ZPM clients should verify these signatures before unpacking the package.
Contributor guide
Assessment
This issue has not been assessed yet.