What problem does your feature solve?
Linked to some discussions about supply chain https://github.com/orgs/stellar/discussions/1923. Compliance with SLSA Level 4 on source, build, provenance and distribution should be a target for all major repos distributing software. Unless I missed something, I think there are some things to do here.
What would you like to see?
Some easy lifts outlined below.
Source & build:
Provenance:
Distribution:
SBOM:
What alternatives are there?
Not an option IMO.
What problem does your feature solve?
Linked to some discussions about supply chain https://github.com/orgs/stellar/discussions/1923. Compliance with SLSA Level 4 on source, build, provenance and distribution should be a target for all major repos distributing software. Unless I missed something, I think there are some things to do here.
What would you like to see?
Some easy lifts outlined below.
Source & build:
Provenance:
Distribution:
SBOM:
What alternatives are there?
Not an option IMO.