Summary
Recognizing the critical role package repositories play in securing open source software ecosystems, this framework lays out voluntary security maturity levels for package repositories. This publication supports Objective 1.2 of CISA's Open Source Software Security Roadmap , which states the goal of "working collaboratively [with relevant working groups] to develop security principles for package managers." This product is provided subject to this Notification and this Privacy & Use policy.