conda-content-trust
Signing and verification tools, geared toward the conda ecosystem
Signing and verification tools, geared toward the conda ecosystem
To install this package, run one of the following:
Based on The Update Framework (TUF), conda-content-trust contains a set of tools to enable package managers like conda to protect against tampering, so that when users obtain a package or data about that package, those users can know whether or not the data is trustworthy (e.g. originally comes from a reliable source and has not been tampered with). A basic library and basic CLI are included to provide signing, verification, and trust delegation functionality. This exists as an alteration of TUF because of the very particular needs of the conda ecosystem. (Developers are encouraged to just use TUF whenever possible!) This tool is general purpose. It is currently used in conda 4.10.1+ to verify package metadata signatures when they are available.
Summary
Signing and verification tools, geared toward the conda ecosystem
Last Updated
Dec 26, 2023 at 15:39
License
BSD-3-Clause
Total Downloads
6.7K
Supported Platforms
GitHub Repository
https://github.com/conda/conda-content-trustDocumentation
https://github.com/conda/conda-content-trust