Fail CI when dependencies in your lockfile lose npm provenance or trusted publisher status
-
Updated
Jan 26, 2026 - TypeScript
Fail CI when dependencies in your lockfile lose npm provenance or trusted publisher status
[PoC] Trusted Publishing verifier for package URLs (purl)
Get trusted publishing and build reproducibility insights for any Rust supply chain
an example of using a trusted publishing (OIDC) to publish a package
TypeScript hello world library with dual ES modules/CommonJS support. Features GitHub Actions trusted publishing to npmjs with Sigstore attestation.
🔒 Fail CI if dependencies in your lockfile lose npm provenance or trusted publisher status, enhancing the security of your projects.
Add a description, image, and links to the trusted-publishing topic page so that developers can more easily learn about it.
To associate your repository with the trusted-publishing topic, visit your repo's landing page and select "manage topics."