Fail CI when dependencies in your lockfile lose npm provenance or trusted publisher status
-
Updated
Apr 9, 2026 - TypeScript
Fail CI when dependencies in your lockfile lose npm provenance or trusted publisher status
Indexing support for Trusted Publishing on PyPI
[PoC] Trusted Publishing verifier for package URLs (purl)
Get trusted publishing and build reproducibility insights for any Rust supply chain
Checks if an npm package version was published via a Trusted Publisher (OIDC/Provenance)
an example of using a trusted publishing (OIDC) to publish a package
anvil: forge-hardened npm publishing for JS/TS libraries. Reproducible builds, OIDC trusted publishing, hard pre-publish gates. Pure bash, zero dependencies.
npm package starter with OIDC trusted publishing, provenance, and CI/CD baked in
TypeScript hello world library with dual ES modules/CommonJS support. Features GitHub Actions trusted publishing to npmjs with Sigstore attestation.
🔒 Fail CI if dependencies in your lockfile lose npm provenance or trusted publisher status, enhancing the security of your projects.
Add a description, image, and links to the trusted-publishing topic page so that developers can more easily learn about it.
To associate your repository with the trusted-publishing topic, visit your repo's landing page and select "manage topics."