getsentry / getsentry/sentry-javascript

Please add trusted publishing to npm packages to improve security

オープン
#18,421 コメント 2 件 リアクション 1 件 担当者 0 名 GitHub で見る
Feature
主要言語
TypeScript
スター
8.7k
フォーク
1.8k
平均マージ
1日 17時間
マージ済み PR(30日)
515

説明

### Problem Statement

Following recent hacks on npm packages, it would be greatly appreciated if you could increase the trust level of the npm packages.

### Solution Brainstorm

- A first and easy step would be generating provenance statements [docs.npmjs.com/generating-provenance-statements](https://docs.npmjs.com/generating-provenance-statements)
- The best case would be adding trusted publishing [docs.npmjs.com/trusted-publishers](https://docs.npmjs.com/trusted-publishers), as this would allow you to get rid of npm tokens, making token compromises not a risk anymore

### Additional Context

Would have opened a PR, but for trusted publishing, the changes mostly need to happen in the npm config of the packages.

### Priority

React with 👍 to help prioritize this issue. Please use comments to provide useful context, avoiding `+1` or `me too`, to help us triage it.

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。