
The npm registry reported a significant increase in adoption of its package provenance and signature verification features, following several high-profile supply chain attacks against popular open-source packages earlier this year.
Provenance attestations, which cryptographically link a published package back to its source repository and build pipeline, were introduced as an opt-in feature but have seen accelerating adoption as enterprise users increasingly require them for dependency approval. Several major frameworks and tooling projects have publicly committed to publishing with provenance going forward.
Security researchers say the shift reflects a broader maturation in how the JavaScript ecosystem handles supply chain risk, though they caution that provenance alone doesn't prevent all attack vectors, such as compromised maintainer accounts publishing legitimately-signed malicious updates.
npm says it is exploring additional verification layers, including stricter publish-time checks, as part of its ongoing security roadmap.