Project "Conda-Forge CVE Mapping"
Project "Conda-Forge CVE Mapping"
The contract concerns the project "Conda-Forge CVE Mapping" , which covers vulnerability handling and dedicated security maintenance for conda-forge, the largest package repository run by its community in the conda ecosystem. As part of five work packages, the contract covers a machine-readable record of the upstream software from which conda-forge packages are built; an openly licensed dataset of the vulnerabilities affecting those packages; the authority for conda-forge to publish its own vulnerability records; and a funded security function for the package archive and the shared systems that build and publish it. The aim of this service is to give the software supply chain of public research the capacity to identify, disclose and repair the vulnerabilities it distributes.