build1 publisher
npm 10.8.2 publishes unauthenticated when you configure Trusted Publishing
A release workflow signed provenance, reached sigstore, then took a 404 on a package its owner has published for months. The registry withholds existence on purpose, so the real fault, a runner bundling npm 10.8.2, never appears in the error.
Publishers:dev.to
Reality
- Evidence74
- Adoption18
- Hype gap+5
- Incentives22