Skip to content

Prominently show the owner of a package #1158

@legendecas

Description

@legendecas

JSR is a new registry and there might (likely) be chances where people can preemptively register a well-known scope name on other registries, like npm. It could improve the supply chain security if JSR could prominently show the owner of a package.

As a reference, npm shows the owners on the right hand side of a package: https://www.npmjs.com/package/@opentelemetry/api. But on JSR, if I jump to a package page through search, https://jsr.io/@opentelemetry/api, there is no owner information on the first glance of the page. Lukily, the scope of https://jsr.io/@opentelemetry was not taken for a malicious intent. But it is still worrisome that there is no prominent information about the authenticity on JSR package page.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    Status

    Needs Triage

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions