It would be interesting to align with other best practices, such as the ones that the Linux Foundation is building. Software Bill of Materials (SBOM) come mind https://openssf.org/technical-initiatives/sbom-tools/
Understanding the packages which make up a Certified DPG is a good practice. Use of this scorecard could be useful too:
https://openssf.org/projects/scorecard/
It would be interesting to align with other best practices, such as the ones that the Linux Foundation is building. Software Bill of Materials (SBOM) come mind https://openssf.org/technical-initiatives/sbom-tools/
Understanding the packages which make up a Certified DPG is a good practice. Use of this scorecard could be useful too:
https://openssf.org/projects/scorecard/