Skip to content

[W3] Supply-chain security, licensing, and trusted publishing #65

Description

@Claudio9701

Outcome

UrbanPy dependencies and releases have an auditable security, license, and provenance disposition.

Parent tasks

  • close the exposed credential and removed malicious workflow incidents
  • complete trusted publishing and remove long-lived PyPI tokens
  • resolve 42 Dependabot alerts, including the SonarQube Action alert
  • investigate the 104 License Compliance findings
  • establish SPDX/license policy, vulnerability SLA, SBOM, and attestations

Acceptance

No unapproved high-severity exposure remains and only reviewed immutable artifacts can be published.

Plan: PR #61

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:securitySecurity, licensing, and supply chainhigh priorityNeed to be addressed ASAProadmapUrbanPy roadmap parent issue

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions