You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The package repository requires users to verify their email address.
The package repository documents their account recovery policy.
The package repository supports strong multi-factor authentication (MFA) via, at minimum, TOTP.
The package repository notifies maintainers via email for critical account security changes, such as password changes or disabling multi-factor authentication.
The package repository implements account security measures like brute force prevention (even with 2FA attempts)
Level 2
To prevent domain resurrection for account takeover via the recovery process, the package repository detects abandoned email domains.
The CLI has functionality to, where possible, automatically remediate known vulnerabilities in dependencies by upgrading them.
The package repository is able to reduce false positives of identified vulnerabilities using static analysis to understand whether a vulnerable code path is actually reachable.
OpenSSF publishes a document called "Principles for Package Repository Security" (ossf/wg-securing-software-repos#37) to rate the security of package managers. The list contains a lot of points we should have a look at long-term.
This issue tracks the current state of security.
hex_-prefixed API key format with GitHub Secret Scanning support #1536)hex_-prefixed API key format with GitHub Secret Scanning support #1536)