Tag: software distribution
-
Simon Willison’s Weblog: PyPI now supports digital attestations
Source URL: https://simonwillison.net/2024/Nov/14/pypi-digital-attestations/#atom-everything Source: Simon Willison’s Weblog Title: PyPI now supports digital attestations Feedly Summary: PyPI now supports digital attestations Dustin Ingram: PyPI package maintainers can now publish signed digital attestations when publishing, in order to further increase trust in the supply-chain security of their projects. Additionally, a new API is available for consumers and…
-
Hacker News: Python PGP proposal poses packaging puzzles
Source URL: https://lwn.net/SubscriberLink/993787/0dad7bd3d8ead026/ Source: Hacker News Title: Python PGP proposal poses packaging puzzles Feedly Summary: Comments AI Summary and Description: Yes **Summary:** The text discusses the transition from PGP signatures to sigstore for signing Python artifacts, highlighting significant implications for software security. Sigstore, embraced by various projects, simplifies the verification process by eliminating the need…
-
Slashdot: Kaspersky Defends Stealth Swap of Antivirus Software on US Computers
Source URL: https://it.slashdot.org/story/24/09/26/1825249/kaspersky-defends-stealth-swap-of-antivirus-software-on-us-computers?utm_source=rss1.0mainlinkanon&utm_medium=feed Source: Slashdot Title: Kaspersky Defends Stealth Swap of Antivirus Software on US Computers Feedly Summary: AI Summary and Description: Yes Summary: The article discusses Kaspersky’s controversial decision to automatically transition U.S. users from its antivirus software to a product from Pango, citing a government ban. This move raises significant concerns about user…