RSSAmplifier

pavel.pink · Apr 21, 2026

Securing the Conda-Forge Supply Chain

0
Sign in to vote or save

This site does not allow itself to be embedded. You can still read it on the original site — the toolbar below keeps your place in the directory.

The past weeks have shown that we need to take a more active stance to secure the conda-forge ecosystem. An overview of Pixi's new dependency cooldown feature, existing protections like disabled post-install scripts and Trusted Publishing with Sigstore, and plans for a community-driven CVE mapping for conda-forge packages.

Read on prefix.dev

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.