An implementation of a pip plugin that verifies PEP-740 attestations before installing a package, and aborts the installation if verification fails (as discussed on the pip issue tracker).
trailofbits/pip-plugin-pep740
Folders and files
| Name | Name | Last commit date | ||
|---|---|---|---|---|