Expand description
verifyPackageProvenance(
options: {
packageName: string;
repo: `${string}/${string}`;
version: `${number}.${number}.${number}${string}`;
} & FetchOptions & {
maxJsonResponseBytes?: number;
maxRekorEntries?: number;
rekorLagBudgetMs?: number;
rekorLagDelaysMs?: readonly number[];
trustMaterial?: TrustMaterial;
verifier?: BundleVerifier;
},
): Promise<PackageProvenance>Verify npm package provenance via sigstore attestations. Checks the certificate chain, issuer identity, and source repository. Returns a PackageProvenance handle for addon verification.
Verification.