Skip to content
This repository has been archived by the owner on Oct 9, 2023. It is now read-only.

npm: mention generating provenance statements #42

Open
UlisesGascon opened this issue Apr 21, 2023 · 1 comment
Open

npm: mention generating provenance statements #42

UlisesGascon opened this issue Apr 21, 2023 · 1 comment

Comments

@UlisesGascon
Copy link

npm recently introduces the Generating provenance statements. I think it will be a good idea to include a reference in the release section

Should I create a PR for that?

cc: @lirantal @ljharb

@ljharb
Copy link
Member

ljharb commented Apr 21, 2023

I really don't think it's a good idea to recommend or link to it yet. Publishing from CI is very unsafe unless using actual two-factor (an automation token is one-factor), and it remains unclear to me what the value of provenance even is, since I'm not aware of any actual incidents it would have prevented.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants