RE: https://fosstodon.org/@jni/116287554201659198
I said digital attestations and `pylock.toml` would have helped with the litellm attack. People asked for more details, so I wrote a blog post explaining why. It also hopefully acts at motivation for people to use:
- Trusted publishing
- Digital attestations
- Lock files, and `pylock.toml` specifically
https://snarky.ca/why-pylock-toml-includes-digital-attestations/
So yes, @jni , I have a "human-readable intro" because I wrote one for you (and the other folks asking me questions on the subject). 😁

