Fail CI when dependencies in your lockfile lose npm provenance or trusted publisher status
-
Updated
Aug 6, 2026 - TypeScript
Fail CI when dependencies in your lockfile lose npm provenance or trusted publisher status
A composite GitHub Action that turns conventional commits into a draft release PR, tags the PR on merge, and stages publishing to npm via OIDC trusted publishing.
Consumer-side integrity verification for Ruby gems
Indexing support for Trusted Publishing on PyPI
A fast, conservative JSON repair library for malformed model output, hand-written config, and almost-JSON text. Repairs common syntax issues and returns clean Python objects.
Trusted Publishing for Docker registries using GitHub Actions OIDC.
Get trusted publishing and build reproducibility insights for any Rust supply chain
Publish npm workspace packages: only the ones the registry is missing. Resolves workspace: protocol dependencies and supports OIDC trusted publishing.
Easily compare the local devices windows release & build version, against broadly available official Windows 11 versioning. Detects silent updating-issues. This Repository also acts as the always up to date web-source of truth, it displays signed info accessible programmatically through designated GitHub pages.
AI-assisted OSS maintainer workflows for PR review, issue triage, security triage, and release notes.
[PoC] Trusted Publishing verifier for package URLs (purl)
Published npm artifact boundary for handshake-protocol-kernel; trusted publishing and MCP metadata.
an example of using a trusted publishing (OIDC) to publish a package
Operational inventory, release policy, and audit tooling for BuiltByEcho npm packages
Supply-chain-hardened release tool for JS/TS libraries. Multi-runner reproducible-build attestation, OIDC trusted publishing, hard pre-publish gates. Pure bash, zero dependencies.
Clean starting template for Hawkynt's C# repositories: standard scaffolding, unified CI/nightly/release pipeline, and the shared nuget-publish Trusted Publishing action.
Advanced GitHub Actions and package supply-chain defense platform for the May 2026 CI/CD compromise wave.
Guide to publishing a CLI tool to seven channels: GitHub Releases, npm trusted publishing (OIDC), Homebrew, Scoop, winget, AUR, and Chocolatey
Read-only scanner: is your npm/PyPI publish CI ready for OIDC trusted publishing? (post classic-token revocation, Dec 9 2025)
Add a description, image, and links to the trusted-publishing topic page so that developers can more easily learn about it.
To associate your repository with the trusted-publishing topic, visit your repo's landing page and select "manage topics."