Series

The software supply chain

Lockfiles, integrity hashes, provenance attestations and install scripts: what each artifact proves, and the narrower claim it actually makes.

Parts
2
Latest
  1. №01
    Ecosystem and production

    Reading a Lockfile: Supply Chain in Practice

    What package-lock.json actually records, what its integrity hashes do and do not prove, and where the real install-time risk sits.

  2. №02
    Ecosystem and production

    The Provenance Was Valid. The Commit Was Not.

    An npm provenance attestation binds a tarball to a repository, a workflow and a commit. Reading the payload shows what it never claims.

Arrow keys to move, Enter to open.