Fail CI when dependencies in your lockfile lose npm provenance or trusted publisher status
-
Updated
Oct 11, 2026 - TypeScript
Fail CI when dependencies in your lockfile lose npm provenance or trusted publisher status
A composite GitHub Action that turns conventional commits into a draft release PR, tags the PR on merge, and stages publishing to npm via OIDC trusted publishing.
Audit, visualize, share, and track your npm org's trust signals.
Consumer-side integrity verification for Ruby gems
A fast, conservative JSON repair library for malformed model output, hand-written config, and almost-JSON text. Repairs common syntax issues and returns clean Python objects.
Indexing support for Trusted Publishing on PyPI
npm Trusted Publishing (OIDC) manager — interactive wizard, batch binding, and a native TypeScript client for the npm trust API
Easily compare the local devices windows release & build version, against broadly available official Windows 11 versioning. Detects silent updating-issues. This Repository also acts as the always up to date web-source of truth, it displays signed info accessible programmatically through designated GitHub pages.
npm tokens will stop publishing in January 2027. go-tokenless switches your GitHub Actions to trusted publishing (OIDC) in one command. CLI, MCP server and Agent Skill.
Trusted Publishing for Docker registries using GitHub Actions OIDC.
Get trusted publishing and build reproducibility insights for any Rust supply chain
Publish npm workspace packages: only the ones the registry is missing. Resolves workspace: protocol dependencies and supports OIDC trusted publishing.
AI-assisted OSS maintainer workflows for PR review, issue triage, security triage, and release notes.
[PoC] Trusted Publishing verifier for package URLs (purl)
QS-DMSS Studio: evidence-first simulation lab for reproducible runs, evidence bundles, campaign comparison, and research-object exports.
Published npm artifact boundary for handshake-protocol-kernel; trusted publishing and MCP metadata.
Read-only scanner: is your npm/PyPI publish CI ready for OIDC trusted publishing? (post classic-token revocation, Dec 9 2025)
Advanced GitHub Actions and package supply-chain defense platform for the May 2026 CI/CD compromise wave.
Operational inventory, release policy, and audit tooling for BuiltByEcho npm packages
To associate your repository with the trusted-publishing topic, visit your repo's landing page and select "manage topics."