{"id":23250555,"url":"https://github.com/aenguerrand/npm-publish-slsa-two-steps","last_synced_at":"2025-08-20T09:30:45.339Z","repository":{"id":266095581,"uuid":"897357827","full_name":"AEnguerrand/npm-publish-slsa-two-steps","owner":"AEnguerrand","description":"Lab repository demonstrates how to create provenance without using the npm CLI and publish a package to npmjs.com with an attached provenance file (not generated by the npm CLI)","archived":false,"fork":false,"pushed_at":"2024-12-15T11:07:05.000Z","size":79,"stargazers_count":0,"open_issues_count":0,"forks_count":0,"subscribers_count":1,"default_branch":"main","last_synced_at":"2024-12-15T11:28:25.819Z","etag":null,"topics":["npmjs","slsa","supply-chain-security"],"latest_commit_sha":null,"homepage":"","language":"JavaScript","has_issues":false,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/AEnguerrand.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2024-12-02T13:49:20.000Z","updated_at":"2024-12-15T11:07:08.000Z","dependencies_parsed_at":"2024-12-02T15:26:05.464Z","dependency_job_id":"587a224f-1dfd-4fae-aa95-5dfc4f56c9bb","html_url":"https://github.com/AEnguerrand/npm-publish-slsa-two-steps","commit_stats":null,"previous_names":["aenguerrand/npm-publish-slsa-two-steps"],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/AEnguerrand%2Fnpm-publish-slsa-two-steps","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/AEnguerrand%2Fnpm-publish-slsa-two-steps/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/AEnguerrand%2Fnpm-publish-slsa-two-steps/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/AEnguerrand%2Fnpm-publish-slsa-two-steps/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/AEnguerrand","download_url":"https://codeload.github.com/AEnguerrand/npm-publish-slsa-two-steps/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":230408180,"owners_count":18220975,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["npmjs","slsa","supply-chain-security"],"created_at":"2024-12-19T09:12:43.716Z","updated_at":"2024-12-19T09:12:44.437Z","avatar_url":"https://github.com/AEnguerrand.png","language":"JavaScript","funding_links":[],"categories":[],"sub_categories":[],"readme":"# npm-publish-slsa-two-steps\n\nThis lab repository demonstrates how to create provenance without using the npm CLI and publish a package to npmjs.com with an attached provenance file (not generated by the npm CLI). This lab was conducted to ensure compatibility with changesets and the external provenance mechanism, even if the package is not directly pushed to npmjs.com.\n\nHere is a table of all GitHub workflows in this repository:\n\n| Workflow File                        | Workflow Name                    | Description                                                                           | Status |\n|--------------------------------------|----------------------------------|---------------------------------------------------------------------------------------|--------|\n| github-attest-predicate.yaml         | Github Attest - Custom Predicate | Based on `action/attest`. Attest a package with a custom predicate and publish it to npm with attached provenance. | :x: |\n| github-attest.yaml                   | Github Attest                    | Based on `action/attest`. Attest a package and publish it to npm with attached provenance.                      | :x: |\n| sigtstorejs.yaml                     | Sigstore JS                      | Workflow for integrating SigstoreJS with your project.                                  |:x: |\n| slsa-generator-nodejs-custom.yaml    | SLSA Generator Custom NodeJS     | Based on `SLSA GitHub Generator`. Generate SLSA provenance using custom logic for NodeJS projects.                      | :white_check_mark: |\n| slsa-generator-nodejs.yaml           | SLSA Generator NodeJS            | Based on `SLSA GitHub Generator`.Generate SLSA Level 3 provenance using the SLSA GitHub Generator for NodeJS. | :white_check_mark:  |\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Faenguerrand%2Fnpm-publish-slsa-two-steps","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Faenguerrand%2Fnpm-publish-slsa-two-steps","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Faenguerrand%2Fnpm-publish-slsa-two-steps/lists"}