Skip to content

Supply Chain Security #7088

@sgammon

Description

@sgammon
Contributor

The Java ecosystem would be appreciative if, given Guava's place as the number 4 artifact worldwide, efforts could be made to ship releases with SBOMs, SLSA provenance, and Sigstore support. This will prepare many many downstream projects and libraries for stronger dependency security.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

P3no SLOpackage=generaltype=otherMiscellaneous activities not covered by other type= labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

    Development

    Participants

    @sgammon@cpovirk@netdpb

    Issue actions

      Supply Chain Security · Issue #7088 · google/guava