getsentry / getsentry/sentry-javascript

Please add trusted publishing to npm packages to improve security

Abierto
#18,421 2 comentarios 1 reacción 0 asignados Ver en GitHub
Feature
Lenguaje dominante
TypeScript
Estrellas
8.7k
Forks
1.8k
Merge medio
1 d 17 h
PR fusionados (30 d)
515

Descripción

### Problem Statement

Following recent hacks on npm packages, it would be greatly appreciated if you could increase the trust level of the npm packages.

### Solution Brainstorm

- A first and easy step would be generating provenance statements [docs.npmjs.com/generating-provenance-statements](https://docs.npmjs.com/generating-provenance-statements)
- The best case would be adding trusted publishing [docs.npmjs.com/trusted-publishers](https://docs.npmjs.com/trusted-publishers), as this would allow you to get rid of npm tokens, making token compromises not a risk anymore

### Additional Context

Would have opened a PR, but for trusted publishing, the changes mostly need to happen in the npm config of the packages.

### Priority

React with 👍 to help prioritize this issue. Please use comments to provide useful context, avoiding `+1` or `me too`, to help us triage it.

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.