Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

publish npm packages with build provenance #1674

Merged
merged 1 commit into from
Feb 26, 2024
Merged

publish npm packages with build provenance #1674

merged 1 commit into from
Feb 26, 2024

Conversation

bdehamer
Copy link
Contributor

@bdehamer bdehamer commented Feb 26, 2024

Updates the releases workflow to publish npm packages with build provenance information.

The build provenance attestation will be attached the package and can be verified with the npm audit signatures command.

Packages published with provenance also get a badge like this when viewed on the npmjs registry.
image

See https://docs.npmjs.com/generating-provenance-statements

@bdehamer bdehamer requested a review from a team as a code owner February 26, 2024 18:54
@bdehamer bdehamer merged commit 9e5eb95 into main Feb 26, 2024
14 checks passed
@bdehamer bdehamer deleted the npm-provenance branch February 26, 2024 19:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants