Skip to content

Commit 17961f1

Browse files
committed
fixup! fixup! Get NPM signing keys from @sigstore/tuf
1 parent db10011 commit 17961f1

File tree

2 files changed

+4
-2
lines changed

2 files changed

+4
-2
lines changed

sources/npmRegistryUtils.ts

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -48,7 +48,9 @@ async function fetchSigstoreTufKeys(): Promise<Array<KeyInfo> | null> {
4848
// See https://github.com/npm/cli/blob/3a80a7b7d168c23b5e297cba7b47ba5b9875934d/lib/utils/verify-signatures.js#L174
4949
let keysRaw: string;
5050
try {
51-
const sigstoreTufClient = await sigstoreTuf.initTUF({cachePath: path.join(folderUtils.getCorepackHomeFolder(), `_tuf`)});
51+
const sigstoreTufClient = await sigstoreTuf.initTUF({
52+
cachePath: path.join(folderUtils.getCorepackHomeFolder(), `_tuf`)
53+
});
5254
keysRaw = await sigstoreTufClient.getTarget(`registry.npmjs.org/keys.json`);
5355
} catch (error) {
5456
console.warn(`Failed to get signing keys from Sigstore TUF repo`, error);

tests/recordRequests.js

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,7 @@ function getRequestHash(input, init) {
2626

2727
if (init) {
2828
for (const key in init) {
29-
if (init[key] === undefined || key === `timeout`) continue;
29+
if (init[key] === undefined || key === `signal`) continue;
3030

3131
switch (key) {
3232
case `headers`:

0 commit comments

Comments
 (0)