Open source projects being compromised and used to spread malware could be a thing of the past. The Linux Foundation’s software signing initiative wants to be a Let’s Encrypt for software releases.
How the Linux Foundation’s Software Signing Combats Supply Chain Attacks