{
  "id": 12646692,
  "title": "Publishing npm Packages with Provenance",
  "url": "https://urgent.news/2026/10/07/publishing-npm-packages-with-provenance",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-07T14:50:51.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/tsweb/publishing-npm-packages-with-provenance-55mh"
  },
  "original_language": "en",
  "account": "Provenance publishing from GitHub Actions with the --provenance flag grants each npm package a unique link to its exact source code and build environment. This ensures the package's tarball precisely matches the GitHub commit and workflow run that created it.\n\nThe provenance statement, a signed attestation logged in the public Sigstore transparency log, contains the repository, commit, and workflow information. npm displays a green \"Built and signed on GitHub Actions\" badge, indicating a trusted build.\n\nTo set this up, a small TypeScript package named \"color-is-dark\" was built using tsup and managed with pnpm. The essential package.json fields include repository.url that matches the GitHub repo, a build script using tsup, and prepack that runs the build automatically during npm publish. A GitHub Actions workflow triggers on release events and runs npm publish --provenance --access public.\n\nThe workflow includes steps to set up .npmrc using an npm automation token that signs the provenance statement, install pnpm, run the build script, and publish to npm. This setup requires a recent npm CLI (11.5 or later) and a repository secret (NPM_TOKEN) stored as a GitHub action secret.\n\nThe benefits of provenance publishing include a transparent, verifiable link to the source code and build process for every package version. This is particularly valuable for small packages used by others in their dependency trees. After setting up the workflow and secret, every subsequent release will carry this verifiable provenance.",
  "summary": "Why provenance Publishing from GitHub Actions with --provenance takes one extra flag and one permission line. In return, every version on npm links back to the exact commit and workflow run that built it. Without provenance, a package on npm is just a tarball someone uploaded. Nothing proves it matches the source on GitHub. A provenance statement is a signed attestation, logged in the public…",
  "key_points": [
    "Provenance publishing links each npm package to its exact source code and build environment.",
    "The provenance statement is a signed attestation logged in the Sigstore transparency log.",
    "npm displays a green \"Built and signed on GitHub Actions\" badge for trusted builds."
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}