2FA and Provenance

Two-Factor Authentication and Provenance

A stolen token is only useful if it can publish without a human, so the registries' defenses target that step. Trusted publishing (npm 2,036 since July 2025, PyPI 2,431 since 2023, crates.io since 2025) replaces stored tokens with short-lived OpenID Connect credentials that a CI run obtains for one repository and workflow; there is nothing on disk to steal. Packages published that way can carry a provenance attestation, signed through Sigstore 69,885 , that links the tarball to the exact commit and workflow that built it (MERN Stack Development, Trusted Publishing sets it up). npm then tightened publishing through 2026 in response to the worms:

As a consumer you can check what you received. npm audit signatures verifies the registry's signature on every installed tarball and any provenance attestations.

Verifying the signatures and attestations of BookNest's dependenciesShell
cd ~/v5-ch1/booknest && npm audit signatures
Output
audited 82 packages in 3s
82 packages have verified registry signatures
1 package has a verified attestation
(use --json --include-attestations to view attestation details)

All 82 tarballs are exactly what npmjs signed, so no mirror or proxy tampered with them. Only proxy-addr came with provenance; Express 5.2.1 24,430 and pg 8.23.0 have none. Provenance also proves only where a package was built, not that its code is benign: a compromised repository builds malware with valid provenance.