Skip to content

Enable supply chain security through npm provenance attestation - #60498

Closed
Jakub Pavlik (pupapaik) wants to merge 1 commit into
microsoft:mainfrom
ExaForce:main
Closed

Enable supply chain security through npm provenance attestation#60498
Jakub Pavlik (pupapaik) wants to merge 1 commit into
microsoft:mainfrom
ExaForce:main

Conversation

@pupapaik

Copy link
Copy Markdown
  • Configure GitHub Actions workflow for secure publishing
  • Enable automatic provenance generation during npm publish
  • Add integrity verification through Sigstore transparency logs

Fixes#60497

@pupapaik

Copy link
Copy Markdown
Author

@microsoft-github-policy-service agree company="Exaforce"

- Configure GitHub Actions workflow for secure publishing
- Enable automatic provenance generation during npm publish
- Add integrity verification through Sigstore transparency logs
Fixes: microsoft#60497
@MartinJohns

Copy link
Copy Markdown
Contributor

#59013

@pupapaik

Copy link
Copy Markdown
Author

#59013

Sorry I missed it. Thanks for pointing it out.

@microsoftMicrosoft (microsoft) locked as resolved and limited conversation to collaborators Oct 15, 2025
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

For Uncommitted BugPR for untriaged, rejected, closed or missing bug

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Enable supply chain security through npm provenance attestation

4 participants

@pupapaik@MartinJohns@sandersn@typescript-bot