https://github.com/eclipse-cbi/best-practices/blob/a872347035b5510ed638a5435a3818fcd375064b/software-supply-chain/osssc-best-practices.md?plain=1#L23