{"_id":"@asidfhiodfugnsdf/hello-world-slsa","_rev":"3-c1bd017c13e6ae483c19db0a58e7261e","name":"@asidfhiodfugnsdf/hello-world-slsa","dist-tags":{"latest":"1.2.17"},"versions":{"0.0.1":{"name":"@asidfhiodfugnsdf/hello-world-slsa","version":"0.0.1","keywords":["hello-world","slsa","provenance"],"author":"","license":"MIT","_id":"@asidfhiodfugnsdf/hello-world-slsa@0.0.1","maintainers":[{"name":"asidfhiodfugnsdf","email":"firstnamedotlastname69@gmail.com"}],"homepage":"https://github.com/sjkdh2ksjdhgj9/npm-test-repo#readme","bugs":{"url":"https://github.com/sjkdh2ksjdhgj9/npm-test-repo/issues"},"dist":{"shasum":"027fb564ba425a0e82f9c9baa8b36cf45629cf97","tarball":"https://registry.npmjs.org/@asidfhiodfugnsdf/hello-world-slsa/-/hello-world-slsa-0.0.1.tgz","fileCount":3,"integrity":"sha512-7HruylUmMehfa84CTNf+bCfuDr9BVjOYHadjaQMIaeFJuGqLRmZV0xizgYoZrUTXpp6WejRnzUexDuf/gQbHWQ==","signatures":[{"sig":"MEUCIBML0Z0SVGsfU+7cTkj4heS3gQp/w0sVopiSwY+eyvRhAiEAt4wdQ0KuHfdJ6PX/nHl9vITkZk5wWontZGMW/+/JWiA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1287},"main":"dist/index.js","types":"dist/index.d.ts","scripts":{"ci":"npm ci","test":"node dist/index.js","build":"tsc"},"_npmUser":{"name":"asidfhiodfugnsdf","email":"firstnamedotlastname69@gmail.com"},"repository":{"url":"git+https://github.com/sjkdh2ksjdhgj9/npm-test-repo.git","type":"git"},"_npmVersion":"11.5.1","description":"A hello world npm package with SLSA 3 provenance","directories":{},"_nodeVersion":"24.7.0","_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.3.0","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/hello-world-slsa_0.0.1_1765562599140_0.3059735260450578","host":"s3://npm-registry-packages-npm-production"}},"1.0.0":{"name":"@asidfhiodfugnsdf/hello-world-slsa","version":"1.0.0","author":"","_id":"@asidfhiodfugnsdf/hello-world-slsa@1.0.0","maintainers":[{"name":"asidfhiodfugnsdf","email":"firstnamedotlastname69@gmail.com"}],"homepage":"https://github.com/sjkdh2ksjdhgj9/npm-test-repo#readme","bugs":{"url":"https://github.com/sjkdh2ksjdhgj9/npm-test-repo/issues"},"dist":{"shasum":"e5dcae97a442f58d31c896b104fe9d6aeab36aad","tarball":"https://registry.npmjs.org/@asidfhiodfugnsdf/hello-world-slsa/-/hello-world-slsa-1.0.0.tgz","fileCount":4,"integrity":"sha512-YZDoqzI7dqhfGlBV+r2LIB5B0/mxA2EHu7bwQpKl9YxBTZmVs2EkW6ZyRF+PNO88InVmagt/ZX1LE3ugL4+80A==","signatures":[{"sig":"MEUCIQDHtRELIAVJj+NZQSsPzicUt77ZYQ+Q5DLrNWh1YZ53EQIgOG41Oq2fsnqMF8+qB1RK+MLmV7EmPgAfIN1MkjalmZc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@asidfhiodfugnsdf%2fhello-world-slsa@1.0.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2683},"main":"dist/index.js","types":"dist/index.d.ts","gitHead":"f27d25ccf52a4c054a0fc0eab6ebf4db77873760","scripts":{"test":"node dist/index.js","build":"tsc","release":"yarn build && changeset publish"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ca38eb84-8584-49a0-a4e4-c978160dc486"}},"repository":{"url":"git+https://github.com/sjkdh2ksjdhgj9/npm-test-repo.git","type":"git"},"_npmVersion":"11.7.0","description":"A hello world npm package with SLSA 3 provenance","directories":{},"_nodeVersion":"20.19.6","_hasShrinkwrap":false,"packageManager":"yarn@4.2.2","devDependencies":{"typescript":"^5.3.0","@types/node":"^20.0.0","@changesets/cli":"^2.27.8"},"_npmOperationalInternal":{"tmp":"tmp/hello-world-slsa_1.0.0_1765563608538_0.40321901830691775","host":"s3://npm-registry-packages-npm-production"}},"1.2.17":{"name":"@asidfhiodfugnsdf/hello-world-slsa","version":"1.2.17","description":"A hello world npm package with SLSA 3 provenance","main":"dist/index.js","types":"dist/index.d.ts","packageManager":"yarn@4.2.2","scripts":{"ci":"npm ci","build":"tsc","test":"node dist/index.js"},"author":"","repository":{"type":"git","url":"git+https://github.com/sjkdh2ksjdhgj9/npm-test-repo.git"},"devDependencies":{"@changesets/cli":"^2.27.8","@types/node":"^20.19.27","typescript":"^5.3.0"},"_id":"@asidfhiodfugnsdf/hello-world-slsa@1.2.17","bugs":{"url":"https://github.com/sjkdh2ksjdhgj9/npm-test-repo/issues"},"homepage":"https://github.com/sjkdh2ksjdhgj9/npm-test-repo#readme","_integrity":"sha512-hiJZ72MbC4K+9apNmWkMbiYCeyYqySeNeQTPDPng0JnzZfKUOjyh2Ff79RJlT3FarlXKhBFi/hTeqsglu9A6kw==","_resolved":"/home/runner/work/npm-test-repo/npm-test-repo/package-artifact/yarn-package-20244812143-1-1765826891/package.tgz","_from":"file:package-artifact/yarn-package-20244812143-1-1765826891/package.tgz","_nodeVersion":"20.19.6","_npmVersion":"11.7.0","dist":{"integrity":"sha512-hiJZ72MbC4K+9apNmWkMbiYCeyYqySeNeQTPDPng0JnzZfKUOjyh2Ff79RJlT3FarlXKhBFi/hTeqsglu9A6kw==","shasum":"9a2d564a13243f47bf2a57d96ace2e31ae0079a3","tarball":"https://registry.npmjs.org/@asidfhiodfugnsdf/hello-world-slsa/-/hello-world-slsa-1.2.17.tgz","fileCount":5,"unpackedSize":4771,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@asidfhiodfugnsdf%2fhello-world-slsa@1.2.17","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDYxt8ODAQAh5xPeylTGbHw5PdAjmmXOW2SwbRiC63bJQIgFw9YyP+vQVVEfhLvaLd76AbmwttXKtWr3O91OzOr42o="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:6752d0f0-00f3-409b-87a1-aa3e50fad21d"}},"directories":{},"maintainers":[{"name":"asidfhiodfugnsdf","email":"firstnamedotlastname69@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/hello-world-slsa_1.2.17_1765826939243_0.8884743470345069"},"_hasShrinkwrap":false}},"time":{"created":"2025-12-12T18:03:19.068Z","modified":"2025-12-15T19:28:59.700Z","0.0.1":"2025-12-12T18:03:19.282Z","1.0.0":"2025-12-12T18:20:08.673Z","1.2.17":"2025-12-15T19:28:59.375Z"},"bugs":{"url":"https://github.com/sjkdh2ksjdhgj9/npm-test-repo/issues"},"homepage":"https://github.com/sjkdh2ksjdhgj9/npm-test-repo#readme","repository":{"type":"git","url":"git+https://github.com/sjkdh2ksjdhgj9/npm-test-repo.git"},"description":"A hello world npm package with SLSA 3 provenance","maintainers":[{"name":"asidfhiodfugnsdf","email":"firstnamedotlastname69@gmail.com"}],"readme":"# @asidfhiodfugnsdf/hello-world-slsa\n\nA hello world npm package with SLSA 3 provenance and trusted publishing.\n\n## Development\n\n### Prerequisites\n\n- Node.js 20.x\n- Yarn 4.x (via corepack)\n\n### Setup\n\n```bash\ncorepack enable\nyarn install\n```\n\n### Scripts\n\n```bash\nyarn build    # Compile TypeScript\nyarn test     # Run tests\n```\n\n## Releasing\n\nThis package uses:\n- [Changesets](https://github.com/changesets/changesets) for versioning\n- [SLSA 3 Node.js builder](https://github.com/slsa-framework/slsa-github-generator/blob/main/internal/builders/nodejs/README.md) for provenance\n- [npm trusted publishing](https://docs.npmjs.com/generating-provenance-statements) (OIDC) for secure tokenless releases\n\n### One-time setup\n\n1. **First publish** (manual, to create the package on npm):\n   ```bash\n   npm login\n   yarn build\n   npm publish --access=public\n   ```\n\n2. **Configure trusted publishing** on npmjs.com:\n   - Go to https://www.npmjs.com/package/@asidfhiodfugnsdf/hello-world-slsa/access\n   - Under \"Publishing access\", add a trusted publisher:\n     - **Repository owner**: `sjkdh2ksjdhgj9`\n     - **Repository name**: `npm-test-repo`\n     - **Workflow filename**: `publish.yml`\n\n3. **Enable GitHub Actions permissions**:\n   - Go to repo Settings → Actions → General\n   - Enable \"Allow GitHub Actions to create and approve pull requests\"\n\n### Making a release (step by step)\n\n1. **Make your code changes** and commit them\n\n2. **Create a changeset** describing your changes:\n   ```bash\n   yarn changeset\n   ```\n   - Select the package\n   - Choose version bump type (patch/minor/major)\n   - Write a summary of changes\n   - This creates a file in `.changeset/`\n\n3. **Commit and push** the changeset:\n   ```bash\n   git add .changeset\n   git commit -m \"Add changeset for <your change>\"\n   git push origin main\n   ```\n\n4. **Wait for the \"Version Packages\" PR**:\n   - The `publish.yml` workflow runs on push to main\n   - It creates a PR titled \"Version Packages\"\n   - This PR bumps the version in `package.json` and updates the changelog\n\n5. **Review and merge the PR**:\n   - Review the version bump and changelog\n   - Merge the PR to main\n\n6. **Automatic publish with SLSA 3**:\n   - Merging triggers the workflow again\n   - Changesets detects no pending changesets and runs `changeset tag`\n   - SLSA 3 builder builds the package in an isolated environment\n   - Package is published to npm with SLSA 3 provenance attestation\n\n### Verifying provenance\n\nAfter publishing, verify the package provenance:\n\n```bash\nnpm audit signatures\n```\n\nOr use the SLSA verifier:\n```bash\nslsa-verifier verify-npm-package @asidfhiodfugnsdf/hello-world-slsa --source-uri github.com/sjkdh2ksjdhgj9/npm-test-repo\n```\n","readmeFilename":"README.md"}