Skip to content

Support pnpm audit signatures #7909

@StarpTech

Description

@StarpTech

Contribution

Describe the user story

Please see https://github.blog/changelog/2022-07-26-a-new-npm-audit-signatures-command-to-verify-npm-package-integrity/ I also figured out that running pnpm audit signatures does not return any error but run a standard audit. The CLI should be more strict.

Describe the solution you'd like

pnpm audit signatures should check the signatures for all packages that has been published with provenance support.

Describe the drawbacks of your solution

None

Describe alternatives you've considered

Use npm.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions