Fail CI when dependencies in your lockfile lose npm provenance or trusted publisher status
-
Updated
Apr 3, 2026 - TypeScript
Fail CI when dependencies in your lockfile lose npm provenance or trusted publisher status
[PoC] Trusted Publishing verifier for package URLs (purl)
Get trusted publishing and build reproducibility insights for any Rust supply chain
Checks if an npm package version was published via a Trusted Publisher (OIDC/Provenance)
npm package starter with OIDC trusted publishing, provenance, and CI/CD baked in
an example of using a trusted publishing (OIDC) to publish a package
TypeScript hello world library with dual ES modules/CommonJS support. Features GitHub Actions trusted publishing to npmjs with Sigstore attestation.
🔒 Fail CI if dependencies in your lockfile lose npm provenance or trusted publisher status, enhancing the security of your projects.
Add a description, image, and links to the trusted-publishing topic page so that developers can more easily learn about it.
To associate your repository with the trusted-publishing topic, visit your repo's landing page and select "manage topics."