RFC: install trust audit — classified fetch telemetry for package publishers - #917
Open
davidnichols-ops wants to merge 1 commit into
Open
RFC: install trust audit — classified fetch telemetry for package publishers#917davidnichols-ops wants to merge 1 commit into
davidnichols-ops wants to merge 1 commit into
Conversation
Slimmed to audit-only per technical review feedback. Drops blocking modes (require/require-human) which introduced credential-caching attack surfaces and didn't address publish-side compromise. Audit mode classifies every tarball fetch (human/automation/spam_user) and emits structured events with provenance status — zero install-time cost, no blocking, no client-side prompts.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Slimmed revision of #916. Drops all blocking modes (require/require-human) per technical review feedback. Ships audit-only: the registry classifies every tarball fetch as human, automation, or spam_user and emits a structured install-trust-check event. No fetch is ever blocked.
What changed from #916
Why audit-only
The technical review on #916 identified that blocking modes:
Audit mode delivers the real value — publisher visibility into human vs automated traffic — at zero install-time cost.
Files