Preventing accidental NPM leaks by reviewing the final artifact
1 points
2 hours ago
| 1 comment
| github.com
| HN
packattest
2 hours ago
[-]
One thing I’m curious about:

We’ve focused a lot on provenance (where artifacts come from), but less on verifying what actually gets published.

Feels like both are needed — provenance + explicit artifact review.

Curious if others have seen similar issues in other ecosystems (pip, cargo, etc).

reply