Hacker News new | ask | show | jobs
by moeris 1149 days ago
It seems like "artifact provenance" or something would have been a better term. Is this related to SLSA?
1 comments

It’s not directly related to SLSA, although SLSA is an adjacent effort to improve package security!

I think provenance would be misleading in this context, since it’s mostly a side effect of the intended behavior (i.e., publishing without needing to manually configure a shared credential).