You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
There's currently an RFC open on improving the npm ecosystem's security by signing packages using sigstore. I'd like to suggest that semantic-release opt into this functionality whenever npm finalizes their implementation.
Thanks for starting this thread. We are already watching the proposal closely and intend to embrace it. Please don't hesitate to capture more details here about how semantic-release needs to adjust as they become more clear.
There's currently an RFC open on improving the npm ecosystem's security by signing packages using sigstore. I'd like to suggest that semantic-release opt into this functionality whenever npm finalizes their implementation.
Sources:
The text was updated successfully, but these errors were encountered: