Security and quality

Review repository security posture, policy files, alerts, and dependency health.

Overview

Repository security pages now expose code scanning, secret scanning, dependency advisories, SBOM exports, and artifact attestations as their owning data exists.

Policy

Security policy detection already appears in the repository About sidebar when SECURITY.md exists.

SBOM

SPDX JSON SBOM exports are available from the repository SBOM page once a dependency snapshot exists.

Artifact attestations

in-toto Statement JSON documents can be uploaded and downloaded from the repository artifact attestations page.