You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
It would be interesting to align with other best practices, such as the ones that the Linux Foundation is building. Software Bill of Materials (SBOM) come mind https://openssf.org/technical-initiatives/sbom-tools/
Understanding the packages which make up a Certified DPG is a good practice. Use of this scorecard could be useful too: https://openssf.org/projects/scorecard/