OpenSSF accepted AMPEL as a new sandbox project, moving the supply-chain policy engine toward Linux Foundation control so developers and downstream consumers can verify signed metadata about source, builds, dependencies, and releases.
AMPEL Accepted as New OpenSSF Sandbox Project
OpenSSF accepted AMPEL as a new sandbox project, moving the supply-chain policy engine toward Linux Foundation control so developers and downstream consumers can verify signed metadata about source, builds, dependencies, and releases.
Source: Github