Fail CI when dependencies in your lockfile lose npm provenance or trusted publisher status
-
Updated
Apr 17, 2026 - TypeScript
Fail CI when dependencies in your lockfile lose npm provenance or trusted publisher status
Trusted Publishing for Docker registries using GitHub Actions OIDC.
Indexing support for Trusted Publishing on PyPI
[PoC] Trusted Publishing verifier for package URLs (purl)
Get trusted publishing and build reproducibility insights for any Rust supply chain
an example of using a trusted publishing (OIDC) to publish a package
Checks if an npm package version was published via a Trusted Publisher (OIDC/Provenance)
npm package starter with OIDC trusted publishing, provenance, and CI/CD baked in
Supply-chain-hardened release tool for JS/TS libraries. Multi-runner reproducible-build attestation, OIDC trusted publishing, hard pre-publish gates. Pure bash, zero dependencies.
TypeScript hello world library with dual ES modules/CommonJS support. Features GitHub Actions trusted publishing to npmjs with Sigstore attestation.
🔒 Fail CI if dependencies in your lockfile lose npm provenance or trusted publisher status, enhancing the security of your projects.
Add a description, image, and links to the trusted-publishing topic page so that developers can more easily learn about it.
To associate your repository with the trusted-publishing topic, visit your repo's landing page and select "manage topics."