Recent npm and PyPI attacks highlight the need for more trusted open-source dependencies across civilian agencies. Chainguard ...