Skip to content

Add trusted publishing and provenance metrics #95

@43081j

Description

@43081j

It'd be very useful to be able to list the packages which don't have provenance.

We could have a stricter mode of that where it lists those without trusted/oidc publishing too.

Basically, I imagine some kind of --trusted-publisher=provenance / --trusted-publisher=oidc setting we can turn on

The node modules inspector already visualises this so the logic probably exists somewhere there.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions