Skip to content

docs: Update README.md with npm package provenance#2789

Merged
travi merged 1 commit intosemantic-release:masterfrom
lirantal:patch-1
May 9, 2023
Merged

docs: Update README.md with npm package provenance#2789
travi merged 1 commit intosemantic-release:masterfrom
lirantal:patch-1

Conversation

@lirantal
Copy link
Copy Markdown
Contributor

@lirantal lirantal commented May 8, 2023

What

npm package provenance is a big thing for open-source supply chain security and should receive increased awareness and promotion to help secure the ecosystem of 3rd-party packages.

Why

The npm package provenance setup exists in the semantic-release/npm package readme but it's easily missed out on when someone searches the main project's README.

The change

This PR updates the list of supported features to make the feature easily accessible and promote it for users.

Copy link
Copy Markdown
Member

@travi travi left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thanks, @lirantal!

@travi
Copy link
Copy Markdown
Member

travi commented May 9, 2023

i'm merging despite that cancelled matrix verification since that is related to some known test flakiness that i havent had time to investigate yet

@travi travi changed the title chore: Update README.md with npm package provenance docs: Update README.md with npm package provenance May 9, 2023
@travi travi merged commit f1b0801 into semantic-release:master May 9, 2023
@lirantal
Copy link
Copy Markdown
Contributor Author

lirantal commented May 9, 2023

Thanks Matt!

@github-actions
Copy link
Copy Markdown

🎉 This PR is included in version 21.0.3-beta.1 🎉

The release is available on:

Your semantic-release bot 📦🚀

@github-actions
Copy link
Copy Markdown

github-actions bot commented Jun 2, 2023

🎉 This PR is included in version 21.0.3 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants