Skip to content

Conversation

w3njah
Copy link
Contributor

@w3njah w3njah commented Aug 15, 2025

Intent

At present attestation is created for each individual file in the tar archive.
This behaviour significantly slows down the integrity detection as each file's attestation needs to be verified separately.

This PR brings contracts NPM package in alignment with other NPM packages where we attest the package as a whole.

@w3njah w3njah requested a review from ipekt August 15, 2025 03:42
@w3njah w3njah force-pushed the ITSEC-3246-attest-NPM-package-as-a-whole branch from cb417a3 to 16884a7 Compare August 15, 2025 03:44
@w3njah w3njah requested review from a team as code owners August 15, 2025 03:44
@w3njah w3njah merged commit 4199887 into main Aug 25, 2025
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

Successfully merging this pull request may close these issues.

3 participants