Urgent.News

What's breaking now, across thousands of outlets.

Tech

Publishing npm Packages with Provenance

Why provenance Publishing from GitHub Actions with --provenance takes one extra flag and one permission line. In return, every version on npm links back to the exact commit and workflow run that built it. Without provenance, a package on npm is just a tarball someone uploaded. Nothing proves it matches the source on GitHub. A provenance statement is a signed attestation, logged in the public…

Provenance publishing from GitHub Actions with the --provenance flag grants each npm package a unique link to its exact source code and build environment. This ensures the package's tarball precisely matches the GitHub commit and workflow run that created it.

The provenance statement, a signed attestation logged in the public Sigstore transparency log, contains the repository, commit, and workflow information. npm displays a green "Built and signed on GitHub Actions" badge, indicating a trusted build.

To set this up, a small TypeScript package named "color-is-dark" was built using tsup and managed with pnpm. The essential package.json fields include repository.url that matches the GitHub repo, a build script using tsup, and prepack that runs the build automatically during npm publish. A GitHub Actions workflow triggers on release events and runs npm publish --provenance --access public.

The workflow includes steps to set up .npmrc using an npm automation token that signs the provenance statement, install pnpm, run the build script, and publish to npm. This setup requires a recent npm CLI (11.5 or later) and a repository secret (NPM_TOKEN) stored as a GitHub action secret.

The benefits of provenance publishing include a transparent, verifiable link to the source code and build process for every package version. This is particularly valuable for small packages used by others in their dependency trees. After setting up the workflow and secret, every subsequent release will carry this verifiable provenance.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Designing a Scalable CI/CD Pipeline for Rails Apps on AWS

Designing a Scalable CI/CD Pipeline for Rails Apps on AWS Introduction Continuous integration and delivery are essential for shipping reliable Rails applications quickly.

  • AWS services used for CI/CD pipeline: CodeCommit, CodeBuild, CodePipeline, Elastic Beanstalk
  • Pipeline stages: Source, Build, Deploy with Elastic Beanstalk for deployment
  • Monitoring and rollback: CloudWatch for performance metrics, Elastic Beanstalk for version rollback

More from Wednesday 7 October →