npmreport

npm gives maintainers mechanisms to verifiably establish how a package was published.

Staged publishing
Published through npm's staged flow, prepared and reviewed before it goes live. npm docs ↗
Trusted publisher
Published from CI over OIDC, with no long-lived npm token to leak or steal. npm docs ↗
Provenance
A signed link from the published package back to the exact source commit and build. npm docs ↗
None
No verifiable signal. The release rests on the maintainer's account and token alone, so a compromise there can ship malware unnoticed.

In the summary, staged publishing and trusted publisher both count as strong trust; provenance is a weaker positive; none is the one to check.

Audit of Lit, generated . This is a read-only snapshot.
Run your own audit →

Audit of Lit

Re-run this audit
Tracking daily next

Progress over time

Strong trust
38.5% (5) staged or trusted
Any trust
69.2% (9) incl. provenance
No trust signal
30.8% (4) no trust metadata detected
Strong trust Any trust No trust signal
0%50%100%6/308/259/8
  1. ...
    9/13 any trust
  2. [viewing]
    0/0 any trust
  3. 9/13 any trust
  4. 9/13 any trust
  5. ...
    9/13 any trust
  6. ...
    9/13 any trust
  7. ...
    9/13 any trust
  8. 0/0 any trust
  9. 9/13 any trust
  10. 9/13 any trust
  11. 9/13 any trust
  12. 9/13 any trust
  13. 0/0 any trust
  14. ...
    9/13 any trust
  15. ...
    9/13 any trust
  16. 9/13 any trust
  17. 9/13 any trust
  18. 0/0 any trust
In scope
0
Staged publish
0
Trusted publisher
0
Provenance only
0
No trust signal
0
Deprecated latest
0
0 packages · click a column to sort
Package trust level report