-
-
Notifications
You must be signed in to change notification settings - Fork 1.7k
Open
Labels
Description
Problem Statement
Following recent hacks on npm packages, it would be greatly appreciated if you could increase the trust level of the npm packages.
Solution Brainstorm
- A first and easy step would be generating provenance statements docs.npmjs.com/generating-provenance-statements
- The best case would be adding trusted publishing docs.npmjs.com/trusted-publishers, as this would allow you to get rid of npm tokens, making token compromises not a risk anymore
Additional Context
Would have opened a PR, but for trusted publishing, the changes mostly need to happen in the npm config of the packages.
Priority
React with 👍 to help prioritize this issue. Please use comments to provide useful context, avoiding +1 or me too, to help us triage it.
tnkuehne
Metadata
Metadata
Assignees
Labels
Projects
Status
No status