top | item 35649964

(no title)

moeris | 2 years ago

It seems like "artifact provenance" or something would have been a better term. Is this related to SLSA?

discuss

order

woodruffw|2 years ago

It’s not directly related to SLSA, although SLSA is an adjacent effort to improve package security!

I think provenance would be misleading in this context, since it’s mostly a side effect of the intended behavior (i.e., publishing without needing to manually configure a shared credential).