getsentry / getsentry/sentry-javascript
Please add trusted publishing to npm packages to improve security
- Langage dominant
- TypeScript
- Étoiles
- 8.7k
- Forks
- 1.8k
- Merge moyen
- 1 j 17 h
- PR mergées (30 j)
- 515
Description
### Problem Statement
Following recent hacks on npm packages, it would be greatly appreciated if you could increase the trust level of the npm packages.
### Solution Brainstorm
- A first and easy step would be generating provenance statements [docs.npmjs.com/generating-provenance-statements](https://docs.npmjs.com/generating-provenance-statements)
- The best case would be adding trusted publishing [docs.npmjs.com/trusted-publishers](https://docs.npmjs.com/trusted-publishers), as this would allow you to get rid of npm tokens, making token compromises not a risk anymore
### Additional Context
Would have opened a PR, but for trusted publishing, the changes mostly need to happen in the npm config of the packages.
### Priority
React with 👍 to help prioritize this issue. Please use comments to provide useful context, avoiding `+1` or `me too`, to help us triage it.
Guide de contribution
Ouvrir le guide de contribution
Évaluation
Cette issue n'a pas encore été évaluée.