Beta Testing needed for my package Trustcheck
Consolidates sigstore attestation verification and vulnerability scans into one pre-install CLI check.
Verify PyPI package attestations and improve Python supply-chain security
Catches supply-chain attacks by verifying cryptographic attestations before pip install.
Python developers and DevOps teams
pip-audit · sigstore · safety
Consolidates sigstore attestation verification and vulnerability scans into one pre-install CLI check.
Tests PyPI packages across 6 Python environments with live pass-rate dashboard.
nodei.co already does this for npm; this is the Python clone without differentiation.
PyPI package with zero description — no README, no docs, no idea what it does.
Real-time PyPI trends with Claude AI summaries, but analytics dashboards exist (npm trends, libraries.io).
Yet another package proxy when Sonatype, Verdaccio, and Cloudsmith already own this space.