Skip to content
Merged
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Next Next commit
feat: include fetched attestation bundles in _attestations
When verifyAttestations is enabled, pacote already fetches the full
sigstore attestation bundles from the registry and uses them for
verification. However, the fetched bundles are discarded after
verification, and only the lightweight dist.attestations metadata
(URL + predicate type) is saved to mani._attestations.

This change expands _attestations to include the fetched bundles as
a 'bundles' property, making the complete sigstore bundles (DSSE
envelopes, verification material, tlog entries) available to
downstream consumers like the npm CLI without requiring a re-fetch.

Co-authored-by: Copilot <[email protected]>
  • Loading branch information
Mitch Denny and Copilot committed Mar 2, 2026
commit 44f88cc88dfce2565d98cb9d0b4b283ac6a4fc9a
2 changes: 1 addition & 1 deletion lib/registry.js
Original file line number Diff line number Diff line change
Expand Up @@ -341,7 +341,7 @@ class RegistryFetcher extends Fetcher {
})
}
}
mani._attestations = dist.attestations
mani._attestations = { ...dist.attestations, bundles: attestations }

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Let's hang these off of another _ attribute. I'd hate for attestations to add a bundles attribute some time in the future and make this a huge problem.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Agreed with this recommendation 😄

} else {
mani._attestations = dist.attestations
}
Expand Down