Beta Testing needed for my package Trustcheck
Catches supply-chain attacks by verifying cryptographic attestations before pip install.
Verify PyPI package attestations and improve Python supply-chain security
Consolidates sigstore attestation verification and vulnerability scans into one pre-install CLI check.
Python developers, DevSecOps engineers
pip-audit · sigstore · OSV-Scanner
Catches supply-chain attacks by verifying cryptographic attestations before pip install.
Revocable AI signatures solve version drift, but 'no key management' contradicts security basics.
Real-time PyPI trends with Claude AI summaries, but analytics dashboards exist (npm trends, libraries.io).
Tests PyPI packages across 6 Python environments with live pass-rate dashboard.
nodei.co already does this for npm; this is the Python clone without differentiation.
Yet another package proxy when Sonatype, Verdaccio, and Cloudsmith already own this space.