Comprehensive guide to securing npm package publishing workflows in response to recent supply chain attacks. Covers eliminating access tokens in favor of OIDC Trusted Publishers, implementing 2FA requirements, using password managers, pinning GitHub Actions dependencies, checking in lock files, and restricting publishing

7m read time From zachleat.com
Post cover image
Table of contents
Security Checklist #Additional Reading #

Sort: