supply-chain · severity medium
Package provenance
Share of widely-used npm packages published without a provenance attestation linking the artefact to the source that built it.
Measured every Sunday · last updated
How it is measured
Bulk npm metadata: attestations and signatures on the latest release.
Why it matters
A signature proves the registry served what the publisher uploaded; only provenance links the artefact to the source commit and build that produced it. Without it, a compromised publisher account or build step is undetectable. ~85% lack provenance.
Limits of this measurement
npm only. PyPI is excluded rather than counted as unsigned, because its JSON API does not surface PEP 740 attestations — absence of evidence is not evidence of absence. The earlier framing (counting only unsigned) read 0% because npm signs everything; the real gap is build provenance, which is why signed_only is a failure state.
The base rate
Measured over the full population of packages, from public bulk sources.
Every segment
Pick one to see the citable answer, with its trend and methodology.
From the newsletter
Where this base rate turned up as a real, fixable exposure.
Slices below 100 measured members are withheld rather than shown with a wide interval — an absent country or issuer means too little data, not zero failures. Licensed CC BY 4.0. Machine-readable data per segment: append .json or .csv to its URL.