- Published on
The past weeks have shown that we need to take a more active stance to secure the conda-forge ecosystem. An overview of Pixi's new dependency cooldown feature, existing protections like disabled post-install scripts and Trusted Publishing with Sigstore, and plans for a community-driven CVE mapping for conda-forge packages.