How does Bun ensure supply chain security when publishing to the registry? #17189
Unanswered
thelovekesh
asked this question in
Q&A
Replies: 1 comment
-
There is And this feature seems very platform specific (so people can verify it's legitimacy) Other then that I don't think npm has any signing. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Recently, Bun introduced the
publish
command for publishing packages to the npm registry. I'm not entirely sure if the npm CLI performs any form of signing before publishing a package, but at some stage, it generates a signature fromname + version + shasum
.However, when creating a tarball and sending it to the registry, how can we be sure that neither the tarball nor the metadata has been tampered with?
Beta Was this translation helpful? Give feedback.
All reactions