npmreport

npm gives maintainers mechanisms to verifiably establish how a package was published.

Staged publishing
Published through npm's staged flow, prepared and reviewed before it goes live. npm docs ↗
Trusted publisher
Published from CI over OIDC, with no long-lived npm token to leak or steal. npm docs ↗
Provenance
A signed link from the published package back to the exact source commit and build. npm docs ↗
None
No verifiable signal. The release rests on the maintainer's account and token alone, so a compromise there can ship malware unnoticed.

In the summary, staged publishing and trusted publisher both count as strong trust; provenance is a weaker positive; none is the one to check.

Audit of Sveltejs, generated . This is a read-only snapshot.
Run your own audit →

Audit of Sveltejs

Re-run this audit
Tracking daily next

Progress over time

Strong trust
47.2% (17) staged or trusted
Any trust
55.6% (20) incl. provenance
No trust signal
44.4% (16) no trust metadata detected
Strong trust Any trust No trust signal
0%50%100%8/248/258/268/30
  1. 20/36 any trust
  2. 20/36 any trust
  3. 0/0 any trust
  4. ...
    20/36 any trust
  5. 20/36 any trust
  6. 20/36 any trust
  7. [viewing]
    0/0 any trust
  8. 20/36 any trust
  9. 20/36 any trust
  10. 20/36 any trust
  11. 20/36 any trust
  12. 0/0 any trust
  13. 20/36 any trust
In scope
0
Staged publish
0
Trusted publisher
0
Provenance only
0
No trust signal
0
Deprecated latest
0
0 packages · click a column to sort
Package trust level report