Skip to content

Provide provenance to packages in npmjs.org #164

@viccuad

Description

@viccuad

For our published packages, make use of Sigstore as we are doing on other parts of the project to provide a signed provenance of the builds.

More info:
https://docs.npmjs.com/generating-provenance-statements
https://slsa.dev
https://sigstore.dev

Acceptance criteria

  • Update the release GH jobs to create the release artifacts with provenance included

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions