{"_id":"@0-draft/sigil","_rev":"3-e83694d53de8aae80bd320ec26bfef20","name":"@0-draft/sigil","dist-tags":{"latest":"0.0.2"},"versions":{"0.0.0":{"name":"@0-draft/sigil","version":"0.0.0","keywords":["supply-chain-security","sigstore","slsa","openssf","scorecard","provenance","template"],"license":"MIT","_id":"@0-draft/sigil@0.0.0","maintainers":[{"name":"kanywst","email":"kanywst12@gmail.com"}],"homepage":"https://github.com/0-draft/sigil","bugs":{"url":"https://github.com/0-draft/sigil/issues"},"dist":{"shasum":"4884daf37c1b93d507a6af5b76d7b311517d2d44","tarball":"https://registry.npmjs.org/@0-draft/sigil/-/sigil-0.0.0.tgz","fileCount":7,"integrity":"sha512-AziaHAGtcA9kBGfwPwl/j/BEGpL8ObFJGpPXL1O16KYS9wSLJKm4c7Tr9WDZxaD2uB5okW7e8yCOSu/VuOADgw==","signatures":[{"sig":"MEQCIHmvBTWGSKvCo0j1vWTjvvYmdi0Elwf/EJuF390hQBSTAiAiS5k5hu8+fTT8RE3IibJytUI7LFeIEFMPtTwgAF+xAw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":7601},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=24"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"73ac8afb0d2247276c0ace7ff66b2c8325f9cdb5","scripts":{"lint":"biome check . && markdownlint-cli2 \"**/*.md\"","test":"vitest run","audit":"npm audit --audit-level=moderate","build":"tsc -p tsconfig.build.json","check":"npm run lint && npm run typecheck && npm run test && npm run audit && npm run build","format":"biome format --write .","typecheck":"tsc --noEmit","pin-actions":"bash scripts/pin-actions.sh"},"_npmUser":{"name":"kanywst","email":"kanywst12@gmail.com"},"repository":{"url":"git+https://github.com/0-draft/sigil.git","type":"git"},"_npmVersion":"11.7.0","description":"a github template for repos that ship under signature, end to end.","directories":{},"_nodeVersion":"25.4.0","publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.0.0","typescript":"^6.0.3","@biomejs/biome":"^2.4.13","markdownlint-cli2":"^0.22.0"},"_npmOperationalInternal":{"tmp":"tmp/sigil_0.0.0_1777461881884_0.16173229090844177","host":"s3://npm-registry-packages-npm-production"}},"0.0.1":{"name":"@0-draft/sigil","version":"0.0.1","keywords":["supply-chain-security","sigstore","slsa","openssf","scorecard","provenance","template"],"license":"MIT","_id":"@0-draft/sigil@0.0.1","maintainers":[{"name":"kanywst","email":"kanywst12@gmail.com"}],"homepage":"https://github.com/0-draft/sigil","bugs":{"url":"https://github.com/0-draft/sigil/issues"},"dist":{"shasum":"a1ae12e1e0a359aacface429e7f5d0293e7267a0","tarball":"https://registry.npmjs.org/@0-draft/sigil/-/sigil-0.0.1.tgz","fileCount":7,"integrity":"sha512-AfcR609cXTrVcaiyqNDzHAawyvLkeyIDfEUKsEvXl2sDEsq7Ovh08meNsS6buH5SzS2WwU1qwXGasWBZUq8hLw==","signatures":[{"sig":"MEYCIQDxuw41qT6VAOnXgnEc1X7CsV2RW6BtzgiaxLcHbR4ugwIhAP8GnNsoqd7svDDtcjScFh3BRiCpUkwRCPCMCb5ch9Zb","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@0-draft%2fsigil@0.0.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":7601},"main":"./dist/index.js","type":"module","_from":"file:0-draft-sigil-0.0.1.tgz","types":"./dist/index.d.ts","engines":{"node":">=24"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"lint":"biome check . && markdownlint-cli2 \"**/*.md\"","test":"vitest run","audit":"npm audit --audit-level=moderate","build":"tsc -p tsconfig.build.json","check":"npm run lint && npm run typecheck && npm run test && npm run audit && npm run build","format":"biome format --write .","typecheck":"tsc --noEmit","pin-actions":"bash scripts/pin-actions.sh"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:f2349830-0286-48df-8819-c08f5e3a224f"}},"_resolved":"/home/runner/work/sigil/sigil/0-draft-sigil-0.0.1.tgz","_integrity":"sha512-AfcR609cXTrVcaiyqNDzHAawyvLkeyIDfEUKsEvXl2sDEsq7Ovh08meNsS6buH5SzS2WwU1qwXGasWBZUq8hLw==","repository":{"url":"git+https://github.com/0-draft/sigil.git","type":"git"},"_npmVersion":"11.11.0","description":"a github template for repos that ship under signature, end to end.","directories":{},"_nodeVersion":"24.14.1","publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.0.0","typescript":"^6.0.3","@biomejs/biome":"^2.4.13","markdownlint-cli2":"^0.22.0"},"_npmOperationalInternal":{"tmp":"tmp/sigil_0.0.1_1777462995009_0.33567970517799695","host":"s3://npm-registry-packages-npm-production"}},"0.0.2":{"name":"@0-draft/sigil","version":"0.0.2","description":"a github template for repos that ship under signature, end to end.","type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"engines":{"node":">=24"},"publishConfig":{"access":"public","provenance":true},"scripts":{"build":"tsc -p tsconfig.build.json","lint":"biome check . && markdownlint-cli2 \"**/*.md\"","format":"biome format --write .","typecheck":"tsc --noEmit","test":"vitest run","audit":"npm audit --audit-level=moderate","check":"npm run lint && npm run typecheck && npm run test && npm run audit && npm run build","pin-actions":"bash scripts/pin-actions.sh"},"devDependencies":{"@biomejs/biome":"^2.4.13","markdownlint-cli2":"^0.22.0","typescript":"^6.0.3","vitest":"^4.0.0"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/0-draft/sigil.git"},"homepage":"https://github.com/0-draft/sigil","bugs":{"url":"https://github.com/0-draft/sigil/issues"},"keywords":["supply-chain-security","sigstore","slsa","openssf","scorecard","provenance","template"],"_id":"@0-draft/sigil@0.0.2","_integrity":"sha512-V/UBG/HZi4kPouykYNY7l4Jwh9TM2VEqVjMTkn140rSZDN95bXX2EJ5XF+WcWo+j3sWiXrwrps5jRE8/M7+tkw==","_resolved":"/home/runner/work/sigil/sigil/0-draft-sigil-0.0.2.tgz","_from":"file:0-draft-sigil-0.0.2.tgz","_nodeVersion":"24.14.1","_npmVersion":"11.11.0","dist":{"integrity":"sha512-V/UBG/HZi4kPouykYNY7l4Jwh9TM2VEqVjMTkn140rSZDN95bXX2EJ5XF+WcWo+j3sWiXrwrps5jRE8/M7+tkw==","shasum":"c4a60c5f7f2339d84d267c3dbe189779094c1f24","tarball":"https://registry.npmjs.org/@0-draft/sigil/-/sigil-0.0.2.tgz","fileCount":7,"unpackedSize":7601,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@0-draft%2fsigil@0.0.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIF6dq5MxLYbuDHmCD5h+jhr9hwRgSSmBNtQCD/q4XE65AiBP9uV4givfkvahPTk4yWxLka6EP/UUuWMobtTOAgNFsw=="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:f2349830-0286-48df-8819-c08f5e3a224f"}},"directories":{},"maintainers":[{"name":"kanywst","email":"kanywst12@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/sigil_0.0.2_1777463539927_0.6567049146418842"},"_hasShrinkwrap":false}},"time":{"created":"2026-04-29T11:24:41.728Z","modified":"2026-04-29T11:52:20.336Z","0.0.0":"2026-04-29T11:24:42.029Z","0.0.1":"2026-04-29T11:43:15.146Z","0.0.2":"2026-04-29T11:52:20.079Z"},"bugs":{"url":"https://github.com/0-draft/sigil/issues"},"license":"MIT","homepage":"https://github.com/0-draft/sigil","keywords":["supply-chain-security","sigstore","slsa","openssf","scorecard","provenance","template"],"repository":{"type":"git","url":"git+https://github.com/0-draft/sigil.git"},"description":"a github template for repos that ship under signature, end to end.","maintainers":[{"name":"kanywst","email":"kanywst12@gmail.com"}],"readme":"<div align=\"center\">\n\n<img src=\"./assets/sigil-mark.svg\" alt=\"sigil\" width=\"160\" />\n\n# sigil\n\n*every release under signature.*\n\n[![scorecard](https://api.securityscorecards.dev/projects/github.com/0-draft/sigil/badge)](https://securityscorecards.dev/viewer/?uri=github.com/0-draft/sigil)\n[![ci](https://github.com/0-draft/sigil/actions/workflows/ci.yml/badge.svg)](https://github.com/0-draft/sigil/actions/workflows/ci.yml)\n[![license](https://img.shields.io/badge/license-MIT-blue.svg)](./LICENSE)\n\n</div>\n\nfork it. push. your release ships with sigstore signatures, slsa v1.0 provenance, and npm trusted publisher.\nno `NPM_TOKEN`. no path to publish without provenance.\n\n## the chain\n\n```mermaid\nflowchart TB\n    src[\"1. source<br/>gitsign + signed-commit branch protection\"]\n    deps[\"2. deps<br/>npm ci --ignore-scripts + lockfile + dependabot\"]\n    bld[\"3. build<br/>harden-runner + SHA-pinned actions\"]\n    pub[\"4. publish<br/>npm OIDC --provenance + cosign sign-blob\"]\n    dst[\"5. distribute<br/>npm registry attestation\"]\n    con[\"6. consume<br/>verify.sh: audit + cosign + slsa-verifier\"]\n\n    src --> deps --> bld --> pub --> dst --> con\n\n    classDef src  fill:#f05032,stroke:#000,color:#fff\n    classDef deps fill:#cb3837,stroke:#000,color:#fff\n    classDef bld  fill:#fbca04,stroke:#000,color:#000\n    classDef pub  fill:#2ea44f,stroke:#000,color:#fff\n    classDef dst  fill:#7a52d6,stroke:#000,color:#fff\n    classDef con  fill:#326ce5,stroke:#000,color:#fff\n\n    class src src\n    class deps deps\n    class bld bld\n    class pub pub\n    class dst dst\n    class con con\n```\n\nif any link breaks, the next step refuses the input. that is the only behaviour.\n\n## use this template\n\n```bash\n# 1. click \"Use this template\" on github\n# 2. clone your new repo\ngit clone https://github.com/<you>/<your-repo>.git\ncd <your-repo>\n\n# 3. rename + sha-pin every action\n./scripts/init.sh <your-org> <your-repo>\n\n# 4. install + verify locally\nnpm ci\nnpm run check\n\n# 5. configure npm trusted publisher on npmjs.com\n#    settings -> packages -> add trusted publisher\n#    repository:  <your-org>/<your-repo>\n#    workflow:    .github/workflows/release.yml\n#    environment: release\n```\n\n`init.sh` prints the `gh api` one-liner to apply branch protection. run it.\n\n## verify a release (consumer side)\n\n```bash\n./scripts/verify.sh @<org>/<repo>@1.0.0\n```\n\nthree independent proofs, three exit codes:\n\n1. `npm audit signatures` — registry-served sigstore attestation\n2. `cosign verify-blob` — workflow identity pinned via OIDC\n3. `slsa-verifier verify-npm-package` — slsa v1.0 provenance\n\nany one fails -> non-zero -> install rejected.\n\n## see also\n\n- [chainscope](https://github.com/0-draft/chainscope) for the conceptual map\n- [docs/github-settings.md](./docs/github-settings.md) for the one-time UI hardening\n- [docs/branch-protection.md](./docs/branch-protection.md) for the branch protection api call\n- [SECURITY.md](./SECURITY.md) for vulnerability reporting\n- [CONTRIBUTING.md](./CONTRIBUTING.md) for contributor rules\n- [MIT](./LICENSE)\n","readmeFilename":"README.md"}