Skip to content

Document SDK package provenance and publishing integrity - #436

Closed
silentgeckoaudit3801 wants to merge 7 commits into
Axionvera:mainfrom
silentgeckoaudit3801:docs/package-provenance
Closed

Document SDK package provenance and publishing integrity#436
silentgeckoaudit3801 wants to merge 7 commits into
Axionvera:mainfrom
silentgeckoaudit3801:docs/package-provenance

Conversation

@silentgeckoaudit3801

Copy link
Copy Markdown
Contributor

Fixes #126.

Adds package provenance and publishing-integrity guidance for SDK releases, including:

  • recommended npm trusted publishing/provenance practices
  • maintainer do/don't guidance for release credentials and local publishing
  • consumer verification steps for package source, lockfile integrity, and release metadata
  • release checklist coverage so provenance stays part of future releases

Validation: static documentation/API review only; no project dependencies or toolchains were run from this environment.

@El-swaggerito

Copy link
Copy Markdown
Contributor
\nThis PR is currently blocked by merge conflicts.\n\nPlease update the branch with the latest main branch and resolve the conflicts before it can be merged.

@silentgeckoaudit3801

Copy link
Copy Markdown
Contributor Author

Closing this PR because the branch history makes the compare include unrelated repository changes after rebasing attempts. I don't want to risk merging anything outside the package-provenance docs scope for #126. I'll reopen from a clean branch if I can get a branch based directly on current main.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Document SDK package provenance and publishing integrity

2 participants