getsentry / getsentry/sentry-javascript

Please add trusted publishing to npm packages to improve security

Aperta
#18,421 2 commenti 1 reazione 0 assegnatari Vedi su GitHub
Feature
Lingua principale
TypeScript
Stelle
8.7k
Fork
1.8k
Merge medio
1g 17h
PR unite (30g)
515

Descrizione

### Problem Statement

Following recent hacks on npm packages, it would be greatly appreciated if you could increase the trust level of the npm packages.

### Solution Brainstorm

- A first and easy step would be generating provenance statements [docs.npmjs.com/generating-provenance-statements](https://docs.npmjs.com/generating-provenance-statements)
- The best case would be adding trusted publishing [docs.npmjs.com/trusted-publishers](https://docs.npmjs.com/trusted-publishers), as this would allow you to get rid of npm tokens, making token compromises not a risk anymore

### Additional Context

Would have opened a PR, but for trusted publishing, the changes mostly need to happen in the npm config of the packages.

### Priority

React with 👍 to help prioritize this issue. Please use comments to provide useful context, avoiding `+1` or `me too`, to help us triage it.

Guida per i contributori

Apri la guida per i contributori

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.