Supply chain provenance checking for npm packages.
Validates SLSA provenance attestations, checks build source transparency, and identifies packages published from CI.
Summary
Functions
Formats the risk summary for display.
Validates that a package has integrity hash.
Checks if a package entry has provenance information.
Returns a supply chain risk summary for the lockfile.
Scans a lockfile for packages with/without provenance.
Checks if a package's registry is trusted.
Functions
Formats the risk summary for display.
Validates that a package has integrity hash.
Checks if a package entry has provenance information.
Returns a supply chain risk summary for the lockfile.
Scans a lockfile for packages with/without provenance.
Checks if a package's registry is trusted.