Skip to content

An implementation of a pip plugin that verifies PEP-740 attestations before installing a package, and aborts the installation if verification fails.

License

Notifications You must be signed in to change notification settings

trailofbits/pip-plugin-pep740

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

11 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Pip plugin pep740

CI PyPI version Packaging status

An implementation of a pip plugin that verifies PEP-740 attestations before installing a package, and aborts the installation if verification fails (as discussed on the pip issue tracker).

About

An implementation of a pip plugin that verifies PEP-740 attestations before installing a package, and aborts the installation if verification fails.

Resources

License

Security policy

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Contributors 3

  •  
  •  
  •