ruff

1 article
sort: new top best
clear filter
0 7/10

Practical multi-layered defense strategy for Python supply chain security covering code linting, dependency pinning with cryptographic hashes, CVE scanning, SBOM generation, and Trusted Publishing with OIDC attestations. Includes real-world attack case studies (ctx, Ultralytics, GhostAction, Shai-Hulud) demonstrating why each defense layer is necessary.

Bernát Gábor PyPI Ruff uv pip-audit CycloneDX Sigstore OIDC Ultralytics YOLO virtualenv tox platformdirs filelock CNCF ctx PHPass Flask Jinja2 Werkzeug MarkupSafe zizmor GhostAction Shai-Hulud
bernat.tech · gaborbernat · 2 days ago · details · hn