guac
guac copied to clipboard
[collector] PyPI packages
Create a PyPI package collector:
The collector should be able to:
- Be configured with a list of packages to collect from, and a URL to the target server
- Either on a poll or watch basis, collect information from packages
- Create SLSA, SBOM or SLSA attestations based on the information collected