Settings

Theme

Trusted Publishing for NPM Packages

docs.npmjs.com

1 points by Ozzie_osman a month ago · 1 comment

Reader

OhMeadhbh a month ago

This kind of misses the point. Or rather... it's necessary but not sufficient. If the goal is to get code you can trust, then you have to trust each package. Origin Integrity will help you with this if you have a list of trusted devs. But what do you do if a trusted dev imports code from an untrusted source?

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection