The blog of dlaa.me · Jul 25, 2024
En Provence [Some thoughts about npm package provenance - and why I have not enabled it]
0Sign in to vote or save
This site does not allow itself to be embedded. You can still read it on the original site — the toolbar below keeps your place in the directory.
Last year, the GitHub blog outlined efforts to secure the Node.js package repository by Introducing npm package provenance . They write: In order to increase the level of trust you have in the npm packages you download from the registry you must have visibility into the process by which the source was translated into the published artifact. This requirement is addressed by npm package provenance:…
Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.