sentry-javascript icon indicating copy to clipboard operation
sentry-javascript copied to clipboard

Please add trusted publishing to npm packages to improve security

Open tnkuehne opened this issue 3 weeks ago • 2 comments

Problem Statement

Following recent hacks on npm packages, it would be greatly appreciated if you could increase the trust level of the npm packages.

Solution Brainstorm

Additional Context

Would have opened a PR, but for trusted publishing, the changes mostly need to happen in the npm config of the packages.

Priority

React with 👍 to help prioritize this issue. Please use comments to provide useful context, avoiding +1 or me too, to help us triage it.

tnkuehne avatar Dec 08 '25 17:12 tnkuehne

JS-1263

linear[bot] avatar Dec 08 '25 17:12 linear[bot]

We actually have a pretty robust publishing process at Sentry - no employees have access to tokens here.

You can reach more about this here: https://byk.im/posts/releasing-packages/. The rest of the pipeline is also open source (and can be audited):

  • https://github.com/getsentry/publish
  • https://github.com/getsentry/craft

We'll leave this open because I think we still want to add provenance statements, but it'll take some time for us to figure this out.

AbhiPrasad avatar Dec 08 '25 17:12 AbhiPrasad