top | item 32388399

Improving NPM Security with Sigstore

21 points| mnkypete | 3 years ago |github.blog

2 comments

order

jacques_chester|3 years ago

Having been involved with early RubyGems work on sigstore support, I am unreasonably excited to see this announcement. The RFC looks thorough and thoughtful and the impact of better signing in npm can't be overstated.

mnkypete|3 years ago

Yeah, besides finally having some progress regarding signing, I think it's great they went with an option that is open and already is gaining traction.