Series
The software supply chain
Lockfiles, integrity hashes, provenance attestations and install scripts: what each artifact proves, and the narrower claim it actually makes.
- Parts
- 2
- Latest
- №01
Ecosystem and productionReading a Lockfile: Supply Chain in Practice
What package-lock.json actually records, what its integrity hashes do and do not prove, and where the real install-time risk sits.
- №02
Ecosystem and productionThe Provenance Was Valid. The Commit Was Not.
An npm provenance attestation binds a tarball to a repository, a workflow and a commit. Reading the payload shows what it never claims.