For the past two months, stacklok trusty has been reporting malicious packages we have detected via our analysis systems. This has been via manual PRs. We would now like to expose an S3 bucket so that we can automate reporting.
For the record packages will be human vetted before creating a report