npm and Sigstore: Provenance Comes to the World's Largest OSS Ecosystem

No ratings

Presented at BlackHat USA 2023 by

At GitHub, we've been hard at work over the last year on a project to secure the Javascript ecosystem by building provenance directly into first-party tooling and partnering with Sigstore to make software signing easy and ubiquitous. GitHub-owned npm is the de facto standard package system for Javascript, which is the world's largest language ecosystem by lines of code. Serving over 70 billion requests per month and accepting around 40k publish events in the average day, npm is popular enough that it's seen more than its fair share of malware attacks and supply chain trojans in the recent past.Mitigating these attacks not only means making technology available to OSS maintainers, but it also means a cultural shift away from the implicit tradition of unwary trust in components and toward a world where we can prove that every ingredient going into our software masterpieces deserves to be there. We will take you inside the effort to make this vision a reality and tackle some of the controversial questions that have come up along the way, making the case that this approach deserves to be copied throughout the world of open source.