npmreport

npm gives maintainers mechanisms to verifiably establish how a package was published.

Staged publishing
Published through npm's staged flow, prepared and reviewed before it goes live. npm docs ↗
Trusted publisher
Published from CI over OIDC, with no long-lived npm token to leak or steal. npm docs ↗
Provenance
A signed link from the published package back to the exact source commit and build. npm docs ↗
None
No verifiable signal. The release rests on the maintainer's account and token alone, so a compromise there can ship malware unnoticed.

In the summary, staged publishing and trusted publisher both count as strong trust; provenance is a weaker positive; none is the one to check.

Audit of Lit, generated . This is a read-only snapshot.
Run your own audit →

Audit of Lit

Re-run this audit
Tracking daily next

Progress over time

Strong trust
0% (0) staged or trusted
Any trust
0% (0) incl. provenance
No trust signal
0% (0) no trust metadata detected
Strong trust Any trust No trust signal
0%50%100%6/308/259/11
  1. [viewing]
    0/0 any trust
  2. 9/13 any trust
  3. 9/13 any trust
  4. 0/0 any trust
  5. ...
    9/13 any trust
  6. 0/0 any trust
  7. 9/13 any trust
  8. 9/13 any trust
  9. ...
    9/13 any trust
  10. ...
    9/13 any trust
  11. ...
    9/13 any trust
  12. 0/0 any trust
  13. 9/13 any trust
  14. 9/13 any trust
  15. 9/13 any trust
  16. 9/13 any trust
  17. 0/0 any trust
  18. ...
    9/13 any trust
  19. ...
    9/13 any trust
  20. 9/13 any trust
  21. 9/13 any trust
  22. 0/0 any trust
In scope
0
Staged publish
0
Trusted publisher
0
Provenance only
0
No trust signal
0
Deprecated latest
0
0 packages · click a column to sort
Package trust level report