This site does not allow itself to be embedded. You can still read it on the original site — the toolbar below keeps your place in the directory.
The past weeks have shown that we need to take a more active stance to secure the conda-forge ecosystem. An overview of Pixi's new dependency cooldown feature, existing protections like disabled post-install scripts and Trusted Publishing with Sigstore, and plans for a community-driven CVE mapping for conda-forge packages.
Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.