npm provenance overview
Quickly see publishing security for a maintainer’s npm packages.
Try an example: ai, antfu, bluwy, danielroe, developit, dominik_g, fb, feross, fredkschott, isaacs, jdalton, mafintosh, mathias, mozilla-npm, natemoo-re, nodejs-foundation, npm-cli-ops, oss-bot, qix, rich_harris, sindresorhus, svelte-admin, tjholowaychuk, tootallnate, typescript-bot, vitebot, vitestbot, wooorm, yusukebe, yyx990803
Packages for
Loading
Packages for
Trusted
These packages were published with trusted publishing, attesting to the package’s provenance and also reducing the risk of credentials being leaked.
Provenance
These packages were published with an attestation that the package contents were generated by a specific CI workflow.
Insecure
These packages were published without any guarantees about where the package contents come from.