The Python packaging ecosystem formalized support for digital attestations through PEP 740, adding index-level mechanisms to help consumers verify software provenance and strengthen trust in published packages. The change reflects a broader push to improve software supply-chain integrity by binding release artifacts to verifiable signing and attestation workflows rather than relying solely on repository trust.
At the same time, open source maintainers are advancing more resilient signing models to reduce dependence on a single release key. One example is FREEON, a Go-based toolset that uses the FROST threshold-signature protocol from RFC 9591 to generate Ed25519 signatures, allowing multiple participants to jointly authorize releases while keeping encrypted secret shares separate. Related tooling such as age for encryption supports this direction by helping protect local key material, underscoring a wider shift toward stronger provenance, distributed trust, and tamper-resistant release processes for open source software.

See the reporting duties and controls this puts on the clock.
4 events from the most recent confirmed update back to the earliest known activity.
A blog post announced FREEON, an open-source Go toolset for generating Ed25519 threshold signatures using the FROST protocol, aimed at reducing single-key coercion risk in software release signing.
The author stated they delivered a talk about FREEON at DEFCON Furs 2025, though the talk was not recorded.
PEP 740, titled "Index support for digital attestations," was published to define support for digital attestations in the Python packaging ecosystem.
The project was renamed from Freon to FREEON after the author learned that Freon is a registered trademark of the Chemours Company.
See what this changes for your reporting obligations and which controls it puts on the clock.
3 references tracked. Mallory keeps watching after this page renders.
soatok.blog
Open sourcepeps.python.org
Open sourceage-encryption.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.