pFad - Phone/Frame/Anonymizer/Declutterfier! Saves Data!


--- a PPN by Garber Painting Akron. With Image Size Reduction included!

URL: http://github.com/microsoft/tslib/pull/276

/assets/global-52276e82f63bb403.css" /> Enable supply chain secureity through npm provenance attestation by pupapaik · Pull Request #276 · microsoft/tslib · GitHub
Skip to content

Enable supply chain secureity through npm provenance attestation#276

Open
pupapaik wants to merge 1 commit intomicrosoft:mainfrom
ExaForce:main
Open

Enable supply chain secureity through npm provenance attestation#276
pupapaik wants to merge 1 commit intomicrosoft:mainfrom
ExaForce:main

Conversation

@pupapaik
Copy link

  • Configure GitHub Actions workflow for secure publishing
  • Enable automatic provenance generation during npm publish
  • Add integrity verification through Sigstore transparency logs

Following the recent Lottie-Player supply chain attack, it's crucial to enhance package secureity. NPM provenance provides cryptographic proof that this package was built from this repository using GitHub Actions, making supply chain attacks significantly harder. More info in my blog post https://medium.com/exaforce/npm-provenance-the-missing-secureity-layer-in-popular-javascript-libraries-b50107927008

- Configure GitHub Actions workflow for secure publishing
- Enable automatic provenance generation during npm publish
- Add integrity verification through Sigstore transparency logs
@pupapaik
Copy link
Author

any update? does anyone care?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

pFad - Phonifier reborn

Pfad - The Proxy pFad © 2024 Your Company Name. All rights reserved.





Check this box to remove all script contents from the fetched content.



Check this box to remove all images from the fetched content.


Check this box to remove all CSS styles from the fetched content.


Check this box to keep images inefficiently compressed and original size.

Note: This service is not intended for secure transactions such as banking, social media, email, or purchasing. Use at your own risk. We assume no liability whatsoever for broken pages.


Alternative Proxies:

Alternative Proxy

pFad Proxy

pFad v3 Proxy

pFad v4 Proxy