Section 03 of 05

What npm, Node, and a deploy do to your code

npm, the software supply chain, Node and its neighbors, and the behavior that only appears once the code is running somewhere you do not control.

A dependency graph, a lockfile and a release pipeline each make a narrow promise, and most incidents happen in the gap between the promise people assume and the one that was made. These articles read the artifacts directly: the lockfile, the attestation payload, the registry response.

Articles
2
Latest
Series
1
  1. №02
    The software supply chain

    The Provenance Was Valid. The Commit Was Not.

    An npm provenance attestation binds a tarball to a repository, a workflow and a commit. Reading the payload shows what it never claims.

  2. №01
    The software supply chain

    Reading a Lockfile: Supply Chain in Practice

    What package-lock.json actually records, what its integrity hashes do and do not prove, and where the real install-time risk sits.

Browse

Other sections

Arrow keys to move, Enter to open.