▲ | madeofpalk 4 hours ago | |
I would like to see more usage of NPM/Github Actions provenance statements https://www.npmjs.com/package/sigstore#provenance through the ecosystem > The NPM CI tokens that don't require 2fa kind of makes it less useful though Use OIDC to publish packages instead of having tokens around that can be stolen or leaked https://docs.npmjs.com/trusted-publishers |