Skip to content

NPM Audit Signatures issue on 11.0.3 #763

Closed
@nicholasgriffintn

Description

@nicholasgriffintn

Hey, just tried publishing our package which does signature checks before going out to NPM.

Errored with the following on those signature checks:

1 package has an invalid attestation:

@semantic-release/[email protected] (https://registry.npmjs.org/)

Someone might have tampered with this package since it was published on the registry!

Seems to be fine with 11.0.2. Also, this version is showing checked on NPM, so not entirely sure on the issue here, maybe something to check out?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions