ecosyste-ms / ecosyste-ms/packages
Add support for recording npm provenance details
Open
enhancement
- Dominant language
- Ruby
- Stars
- 111
- Forks
- 25
- Avg merge
- 3h 47m
- Merged PRs (30d)
- 14
Description
more details in the following links:
- https://github.blog/2023-04-19-introducing-npm-package-provenance/
- https://docs.npmjs.com/generating-provenance-statements
- https://socket.dev/blog/npm-provenance
Contributor guide
Research direction
Read the three linked npm provenance references first to identify the required details. Then locate the package and version metadata API paths in this Ruby service and determine where npm registry data is recorded. Done means npm package provenance details are recorded and exposed by the relevant API behavior.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- node.js, ruby
- Domain
- api, backend, data
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100