{
  "id": 12230584,
  "title": "(Rant) Provenance and npm packages",
  "url": "https://urgent.news/2026/10/05/rant-provenance-and-npm-packages",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-05T21:15:12.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/tsweb/rant-provenance-and-npm-packages-4044"
  },
  "original_language": "en",
  "account": "The author expresses frustration with the npm package manager, stating that they rarely use it despite dabbling with alternatives like Yarn and Pnpm. They criticize npm for its lack of built-in mechanisms for ensuring package integrity, such as verifying that a package was built correctly from source code. The author suggests that npm allows package authors to upload whatever they want without checking, and that security researchers have developed scripts to compare the output of GitHub repositories to their public npm packages to detect malicious publishing. However, they argue that these measures are not sufficient to ensure security. The author advocates for provenance, which is a clear signal that the package was built from source code and can be traced back to its original source. They note that GitHub has begun displaying provenance badges in their packages, which provide metadata about the build process. The author believes that provenance is a crucial step towards ensuring the security and reliability of npm packages, but acknowledges that it can be difficult to implement and understand.",
  "summary": "Here's the thing about me. I'm an overbearing asshole. As such, I don't really like npm. No good reason to speak of. I've dabble with yarn and pnpm, and internal npm registries, and lockfiles and sha hashes and IPFS and all that. I've gone a long time from actually using npm proper. Like, the public npm registry. And I had seen the yarn npm registry (mirror?). I'm like... \"that's cool, but how…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}