BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//programme.europython.eu//europython-2023//speaker//8SJZ
 JT
BEGIN:VTIMEZONE
TZID:Europe/Prague
BEGIN:DAYLIGHT
DTSTART:20220720T000000
TZNAME:CEST
TZOFFSETFROM:+0200
TZOFFSETTO:+0200
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20221030T030000
RDATE:20231029T030000
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20230326T030000
RDATE:20240331T030000
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:PEP 458 a solution not only for PyPI - Kairo de Araujo\, Martin Vr
 achev
DTSTART;TZID=Europe/Prague:20230720T143500
DTEND;TZID=Europe/Prague:20230720T150500
DTSTAMP:20260904T203426Z
UID:pretalx-europython-2023-ETSMPK@programme.europython.eu
DESCRIPTION:[PEP 458](https://peps.python.org/pep-0458/) uses cryptographi
 c signing on [PyPI](https://pypi.org) to protect Python packages against a
 ttackers. The implementation of the PEP inspired the [Repository Service f
 or TUF (RSTUF)](http://repository-service-tuf.readthedocs.io/)\, a project
  [accepted into the OpenSSF sandbox](https://github.com/ossf/tac/pull/137)
 . We identified that the design could benefit other organizations and repo
 sitories looking to secure their software supply chains.\nIn this talk we 
 would answer the following questions: \n- How did the PEP 458 design help 
 to start the Repository Service for TUF (RSTUF)?\n- How could RSTUF be use
 d for PyPI with its millions of packages?\n- How can RSTUF be deployed by 
 any organization at any scale without requiring TUF expertise?\n\nAddition
 ally\, in this talk\, we would give an overview of PEP 458\, how it works\
 , and give a high-level overview of TUF.
LOCATION:South Hall 2A
URL:https://programme.europython.eu/europython-2023/talk/ETSMPK/
END:VEVENT
END:VCALENDAR
