{"repo":"danielroe/provenance-action","free":true,"listed":false,"github":"https://github.com/danielroe/provenance-action","clone":"git clone https://github.com/danielroe/provenance-action.git","description":"Fail CI when dependencies in your lockfile lose npm provenance or trusted publisher status","language":"TypeScript","stars":306,"topics":["github-actions","provenance","security","trusted-publishing"],"license":"MIT","category":"security-tools","readme_excerpt":"danielroe/provenance-action Fail CI when dependencies in your lockfile lose npm provenance, trusted publisher or staged publishing status. [!WARNING] This action is under active development and is only one tool to assist in securing your dependencies. [!NOTE] pnpm users: As of pnpm v10.21, pnpm now has built-in support for trustPolicy in .npmrc , which provides native enforcement of provenance checks. If you're using pnpm v10.21 or later, you may not need this action. See the pnpm documentation for more details. ✨ Features - supports pnpm-lock.yaml , package-lock.json , yarn.lock (v1 and v2+), bun.lock - handles transitives by comparing resolved versions - inline GitHub annotations at the lockfile line - JSON output and optional hard‑fail (default: on) - pure TypeScript, Node 24+ 👉 See it in action: danielroe/provenance-action-test 🚀 Quick start 🔧 Inputs - lockfile (optional): Path to the lockfile. Auto-detected if omitted. - workspace-path (optional): Path to workspace root. Default: . - base-ref (optional): Git ref to compare against. Default: origin/main . - fail-on-downgrade (optional): Controls failure behavior. Accepts true , false , any , or only-provenance-loss . Default: true (which is the same as any ). - fail-on-provenance-change (optional): When true , fail on provenance repository/branch changes. Default: false . 📤 Outputs - downgraded : JSON array of { name, from, to, downgradeType } for detected downgrades. downgradeType is provenance , trusted publisher or","default_branch":null,"files":null,"tree":[],"storefront":"/r/danielroe","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/danielroe/provenance-action/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}