Skip to content

fix: verify registry manifest identity - #516

Open
martinrrm wants to merge 3 commits into
mainfrom
fix/verify-manifest-identity
Open

martinrrm wants to merge 3 commits into
mainfrom
fix/verify-manifest-identity

Conversation

@martinrrm

@martinrrm martinrrm commented Sep 28, 2026 •

Copy link
Copy Markdown

Summary

  • reject signed or attested registry manifests whose name does not match the requested package
  • reject manifests whose explicit _id does not match their name@version
  • reject manifests whose selected version is listed under a different version key
  • preserve normal non-verifying fetch behavior and support aliases, staged versions, and npm-pick-manifest copies

This prevents a compromised registry or mirror from replaying valid metadata from another package and making npm audit signatures treat it as verified for the requested package.

Tests

  • npm test with temporary Git identity for fixture commits
  • full suite passes with 100% coverage
  • ESLint and template-oss checks pass through posttest
  • each replay/identity rejection regression fails when its corresponding guard is removed
  • passing coverage includes valid signed manifests, aliases, manifests with no verification metadata, and existing non-verifying fetch behavior

Release notes

This is a security fix for verification-enabled pacote consumers. Normal installs without signature or attestation verification are unchanged.

Reject signed or attested manifests whose package identity or version does not match the requested registry entry.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@martinrrm
martinrrm requested a review from a team as a code owner September 28, 2026 17:51
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
nkolev92
nkolev92 previously approved these changes Sep 28, 2026
Comment thread lib/registry.js Outdated
Comment thread lib/registry.js Outdated
Comment thread lib/registry.js Outdated
Comment thread lib/registry.js Outdated
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants