Skip to content

Conversation

@beeme1mr
Copy link
Member

@beeme1mr beeme1mr commented Nov 8, 2024

This PR

  • add provenance statement to released artifacts

Notes

Snippet from the NPM docs:

You can generate provenance statements for the packages you publish. This allows you to publicly establish where a package was built and who published a package, which can increase supply-chain security for your packages.

It also adds a cool badge in NPM 😎

Resources

@beeme1mr beeme1mr requested a review from a team as a code owner November 8, 2024 13:21
@beeme1mr beeme1mr merged commit c97d6d1 into main Nov 20, 2024
8 checks passed
@beeme1mr beeme1mr deleted the add-provenance branch November 20, 2024 19:36
wichopy pushed a commit to wichopy/openfeature-js-sdk that referenced this pull request Dec 31, 2024
## This PR

- add provenance statement to released artifacts

### Notes

Snippet from the NPM docs:

> You can generate provenance statements for the packages you publish.
This allows you to publicly establish where a package was built and who
published a package, which can increase supply-chain security for your
packages.

It also adds a cool badge in NPM 😎

### Resources

-
https://docs.npmjs.com/generating-provenance-statements#example-github-actions-workflow

Signed-off-by: Michael Beemer <[email protected]>
Signed-off-by: Will Chou <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants