ecosyste-ms / ecosyste-ms/packages

Add support for recording npm provenance details

Open
#418 0 comments 0 reactions 0 assignees View on GitHub
enhancement
Dominant language
Ruby
Stars
111
Forks
25
Avg merge
3h 47m
Merged PRs (30d)
14

Description

more details in the following links:

- https://github.blog/2023-04-19-introducing-npm-package-provenance/
- https://docs.npmjs.com/generating-provenance-statements
- https://socket.dev/blog/npm-provenance


Fund with Polar

Contributor guide

Open the contributing guide

Research direction

Read the three linked npm provenance references first to identify the required details. Then locate the package and version metadata API paths in this Ruby service and determine where npm registry data is recorded. Done means npm package provenance details are recorded and exposed by the relevant API behavior.

Written by the indexing model from the issue text.

Assessment

Tech stack
node.js, ruby
Domain
api, backend, data
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.