Skip to content

Enforce NPM trusted-publishers as mitigation #294

@RafaelGSS

Description

@RafaelGSS

Due to recent supply chain attacks caused by phishing, relying on this new OIDC authentication for publishing new packages would add a new barrier to those who attempt to introduce malicious code to packages. People still can be tricked into running the action and publishing the package, but I'd say the scope is less sensitive than hijacking the NPM_TOKEN.

I wonder if we can make this a must for OpenJS Foundation projects.

https://docs.npmjs.com/trusted-publishers

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions