nodejs / nodejs/package-maintenance

Suggestion: Provide standards around integrity between source code and published package

Open
#77 85 comments 28 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

discussion vendor
Dominant language
No language data
Stars
423
Forks
147
PR merge metrics
No merged PRs in 30d

Description

Right now, it seems that most maintainers may publish their packages from their local environment. There should be a way to verify what is published against the public source code or specific git sha to maintain transparency of what is being published. Not only will this mitigate out of sync issues or accidents, but will provide greater confidence that additions aren't added as they are published (potentially malicious).

Not sure if this is the best place for this, but after reading through other issues and recent resources I thought I better put this down somewhere. And it brings up the discussion of maintainers permissions to not only package registry, but SCM as well.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No files, tests, or entry points are named. Start by reading the 85-comment discussion and the issue's concerns about public source code, specific git SHAs, package registries, and SCM permissions; the work is not ready until the discussion produces an agreed standard and a defined verification outcome.

Written by the indexing model from the issue text.

Assessment

Tech stack
git
Domain
release, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.