WARNING: THIS SITE IS A MIRROR OF GITHUB.COM / IT CANNOT LOGIN OR REGISTER ACCOUNTS / THE CONTENTS ARE PROVIDED AS-IS / THIS SITE ASSUMES NO RESPONSIBILITY FOR ANY DISPLAYED CONTENT OR LINKS / IF YOU FOUND SOMETHING MAY NOT GOOD FOR EVERYONE, CONTACT ADMIN AT ilovescratch@foxmail.com
Skip to content

Conversation

@tnkuehne
Copy link

@tnkuehne tnkuehne commented Dec 1, 2025

Background

Following recent hacks on npm packages, it would be greatly appreciated if you could increase the trust level of the npm packages.

Summary

I added generation of provenance statements as outlined in this guide from npm: docs.npmjs.com/generating-provenance-statements

Manual Verification

I followed the steps in the npm guide and already contributed this to other npm packages.

Checklist

  • Tests have been added / updated (for bug fixes / features)
  • Documentation has been added / updated (for bug fixes / features)
  • A patch changeset for relevant packages has been added (for bug fixes / features - run pnpm changeset in the project root)
  • I have reviewed this pull request (self-review)

Future Work

Migrating to trusted publishing could further increase security.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant