Outcome
UrbanPy dependencies and releases have an auditable security, license, and provenance disposition.
Parent tasks
- close the exposed credential and removed malicious workflow incidents
- complete trusted publishing and remove long-lived PyPI tokens
- resolve 42 Dependabot alerts, including the SonarQube Action alert
- investigate the 104 License Compliance findings
- establish SPDX/license policy, vulnerability SLA, SBOM, and attestations
Acceptance
No unapproved high-severity exposure remains and only reviewed immutable artifacts can be published.
Plan: PR #61
Outcome
UrbanPy dependencies and releases have an auditable security, license, and provenance disposition.
Parent tasks
Acceptance
No unapproved high-severity exposure remains and only reviewed immutable artifacts can be published.
Plan: PR #61