Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Library security #95

Open
benkehoe opened this issue Apr 27, 2023 · 0 comments
Open

Library security #95

benkehoe opened this issue Apr 27, 2023 · 0 comments

Comments

@benkehoe
Copy link
Owner

@semanur-prenuvo, you asked some questions about aws-sso-lib security over on boto/botocore#1923. This is a better place for discussion. What specifically do you want to know? I would estimate the supply chain security of aws-sso-lib to be a bit above average (MFA on everything, few transitive dependencies), but also not as maximal as I'm sure some high-profile projects have (e.g., I have not gotten around to signing my commits, or if someone managed to compromise the PyPI repo and publish a rogue version I'm not sure how I'd become aware other than user reports). I would note my aws-assume-role-lib has been designated a "critical" project on PyPI, which carries some security requirements like mandatory MFA, and those requirements cover all my projects including aws-sso-lib.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant