Skip to content

Enable Provenance for NPM Package Publishing #1260

@dipakparmar

Description

@dipakparmar

Hi team 👋,

Could you please enable Provenance for the axe-core-npm package when publishing to NPM?

Provenance provides signed, verifiable build metadata that improves supply-chain security and aligns with best practices recommended for open-source packages. Enabling it is straightforward in GitHub Actions.

Reference implementation and discussion:
lerna/lerna#3657 (comment)

This would help downstream consumers (including us) validate package integrity and origin.

Happy to submit a PR, if all good.

Thanks!

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions