Section 03 of 05
What npm, Node, and a deploy do to your code
npm, the software supply chain, Node and its neighbors, and the behavior that only appears once the code is running somewhere you do not control.
A dependency graph, a lockfile and a release pipeline each make a narrow promise, and most incidents happen in the gap between the promise people assume and the one that was made. These articles read the artifacts directly: the lockfile, the attestation payload, the registry response.
- Articles
- 2
- Latest
- Series
- 1
- №02
The software supply chainThe Provenance Was Valid. The Commit Was Not.
An npm provenance attestation binds a tarball to a repository, a workflow and a commit. Reading the payload shows what it never claims.
- №01
The software supply chainReading a Lockfile: Supply Chain in Practice
What package-lock.json actually records, what its integrity hashes do and do not prove, and where the real install-time risk sits.
Browse
Other sections
- Language internals3 articles
- Runtime and performance3 articles
- Frameworks2 articles
- Tooling and build2 articles