We need to package a service and library to validate the integrity of open source package and promote its integration in package repositories, for decentralized, local validation of the supply chain integrity for PURLs used in an application.
- Packaging an open service to validate the integrity of open source package
- Packaging an open library to validate the integrity of open source package
- Promote its integration in ecosystem package repositories,
- Create a CI/CD integration
See also: