Skip to content

Adding 2026 Q2 TAC update for Securing Repos WG#613

Open
steiza wants to merge 2 commits into
mainfrom
wg_repos_q2_2026
Open

Adding 2026 Q2 TAC update for Securing Repos WG#613
steiza wants to merge 2 commits into
mainfrom
wg_repos_q2_2026

Conversation

@steiza

@steiza steiza commented May 22, 2026

Copy link
Copy Markdown
Member

For the upcoming TAC meeting.

Signed-off-by: Zach Steindler <steiza@github.com>
@steiza steiza requested a review from a team as a code owner May 22, 2026 19:06
Signed-off-by: Zach Steindler <steiza@github.com>

@marcelamelara marcelamelara left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @steiza ! I've got a couple questions :)

- Recommend that repositories using trusted publishing disable events from pull_request_target (implemented by npm, PyPI, and Rust Crates)
- Trusted publishing has been hugely valuable as a signal of suspicious packages, as well as a tool for incident response
- Welcome to our new co-chair Mike Fiedler; and thanks to former co-chair Dustin Ingram for his years of service
- We've accepted the Package Analysis and Malicious Packages projects from Securing Critical Projects WG

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could you pls shed some light on what's next for these projects following this transition?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Our intention is for the projects to continue to operate as they were. There is some maintenance in there, but mostly this involves the Malicious Packages project reviewing and publishing submissions from security researchers. Malicious Packages maintainers have also been proactively notifying operators of package repositories during large-scale campaigns, which we greatly appreciate.

There has been increased security researcher activity since about September of last year, as package managers have seen more frequent and larger scale malware campaigns.


### Up Next

- [Make npm install scripts opt-in](https://github.com/npm/rfcs/pull/868)?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What role do you expect the WG to take in this, advising, helping with implementation, etc.?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We would definitely appreciate folks who operate other package repositories to share any relevant experiences and learnings on the RFC. In this particular case, many existing package repositories have avoided making this design decision, but when it's successfully implemented we'll add it to our guidance on https://repos.openssf.org/ for newer / future package repositories to learn from.

@gkunz gkunz left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thank you!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants