Provenance attestation
A signed statement, published with a package, of which source repository and which build produced it.
Without one, a package on a registry is whatever its publisher uploaded, from wherever they built it. With one, the build system signs a record linking the published artefact to a specific repository, commit and workflow, and anybody can check the signature.
On npm this is done through Sigstore: a package published from a supported continuous-integration service can carry an attestation that the registry verifies and displays.
It closes the gap between the source you can read and the package you install, which is where many supply-chain attacks happen.
Reading provenance as a safety check. It proves where a package was built, not that what was built is safe.
Related terms
See Provenance attestation on a real listing
Every term here shows up in the catalogue next to a real result, with the findings published and the limits stated. Free to browse, no account needed.
Open the catalogue