Skip to content

Add package signature verification #57

Description

@CoderSufiyan

Verify package signatures, release signatures, and published checksums during MCP verification.

Acceptance criteria:

  • Support npm signature/provenance evidence where available
  • Support GitHub release signatures and checksums
  • Distinguish signed, unsigned, invalid, and unverifiable artifacts
  • Include evidence in text, JSON, and Markdown reports
  • Never treat an unsigned package as automatically malicious

Depends on: #32 and #36

Milestone: 1.0

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: supply-chainProvenance, vulnerabilities, signatures, and SBOM workblockedBlocked by an unfinished dependencyroadmapPlanned on the public release roadmapversion: 1.0Planned for v1.0.0

    Projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions