intersystems / intersystems/ipm

Signed and Verifiable Packages

Open
#281 2 comments 2 reactions 0 assignees View on GitHub
enhancement prio: medium
Dominant language
ObjectScript
Stars
41
Forks
29
Avg merge
23h 54m
Merged PRs (30d)
4

Description

It is absolutely critical that we have clear and verifiable sightlines into the source code supply chains. Software supply chain is one of the most common attack vectors for hackers. Here's a little overview of the topic: https://blog.tidelift.com/the-state-of-package-signing-across-package-managers

ZPM packages should be signed by their authors and ZPM clients should verify these signatures before unpacking the package.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.