{"id":3556,"date":"2022-08-15T14:45:23","date_gmt":"2022-08-15T05:45:23","guid":{"rendered":"https:\/\/blog-github-com-develop.go-vip.co\/jp\/?p=3556"},"modified":"2022-08-15T15:21:27","modified_gmt":"2022-08-15T06:21:27","slug":"introducing-even-more-security-enhancements-to-npm","status":"publish","type":"post","link":"https:\/\/blog-github-com-develop.go-vip.co\/jp\/2022-08-15-introducing-even-more-security-enhancements-to-npm\/","title":{"rendered":"npm\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u6a5f\u80fd\u3092\u3055\u3089\u306b\u5f37\u5316"},"content":{"rendered":"<p>npm CLI\u3092\u4f7f\u7528\u3057\u305f\u30ed\u30b0\u30a4\u30f3\u304a\u3088\u3073\u30d1\u30d6\u30ea\u30c3\u30b7\u30e5\u306e\u6539\u5584\u3001GitHub\u30a2\u30ab\u30a6\u30f3\u30c8\u3068Twitter\u30a2\u30ab\u30a6\u30f3\u30c8\u306e\u63a5\u7d9a\u3001npm\u3067\u306e\u30d1\u30c3\u30b1\u30fc\u30b8\u306e\u6574\u5408\u6027\u3092\u691c\u8a3c\u3059\u308b\u65b0\u3057\u3044CLI\u30b3\u30de\u30f3\u30c9\u306a\u3069\u3001npm\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u3092\u5f37\u5316\u3057\u307e\u3057\u305f\u3002<\/p>\n<p>JavaScript\u30b3\u30df\u30e5\u30cb\u30c6\u30a3\u3067\u306f\u6bce\u65e550\u5104\u500b\u4ee5\u4e0a\u306e\u30d1\u30c3\u30b1\u30fc\u30b8\u304cnpm\u304b\u3089\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3055\u308c\u3066\u304a\u308a\u3001\u79c1\u305f\u3061\u306f\u958b\u767a\u8005\u306e\u7686\u3055\u3093\u304c\u5b89\u5fc3\u3057\u3066\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3067\u304d\u308b\u3053\u3068\u304c\u3001\u3044\u304b\u306b\u91cd\u8981\u3067\u3042\u308b\u304b\u3092\u8a8d\u8b58\u3057\u3066\u3044\u307e\u3059\u3002\u307e\u305f\u3001npm\u30ec\u30b8\u30b9\u30c8\u30ea\u306e\u7ba1\u7406\u8005\u3068\u3057\u3066\u3001\u79c1\u305f\u3061\u304c\u958b\u767a\u8005\u306e\u7686\u3055\u3093\u304b\u3089\u3055\u3089\u306b\u4fe1\u983c\u3057\u3066\u3082\u3089\u3044\u3001\u30ec\u30b8\u30b9\u30c8\u30ea\u5168\u4f53\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u3092\u5411\u4e0a\u3055\u305b\u308b\u305f\u3081\u306b\u3001\u6539\u5584\u3078\u306e\u6295\u8cc7\u3092\u7d99\u7d9a\u7684\u306b\u5b9f\u65bd\u3059\u308b\u3053\u3068\u304c\u91cd\u8981\u3067\u3042\u308b\u3068\u8003\u3048\u3066\u3044\u307e\u3059\u3002<br \/>\n\u672c\u65e5\u306f\u3001\u5f37\u5316\u3055\u308c\u305fnpm\u306e2FA\u30a8\u30af\u30b9\u30da\u30ea\u30a8\u30f3\u30b9\u304c\u4e00\u822c\u63d0\u4f9b\u3055\u308c\u308b\u3053\u3068\u3092\u304a\u77e5\u3089\u305b\u3059\u308b\u3068\u3068\u3082\u306b\u3001\u30a2\u30ab\u30a6\u30f3\u30c8\u3068\u30d1\u30c3\u30b1\u30fc\u30b8\u306e\u691c\u8a3c\u30d7\u30ed\u30bb\u30b9\u306b\u5bfe\u3057\u3066\u5b9f\u65bd\u3055\u308c\u305f\u8ffd\u52a0\u6295\u8cc7\u306b\u3064\u3044\u3066\u3054\u7d39\u4ecb\u3057\u307e\u3059\u3002<\/p>\n<p>\u4eca\u56de\u3001npm\u306b\u4ee5\u4e0b\u306e\u3088\u3046\u306a\u6539\u5584\u3092\u5b9f\u65bd\u3057\u307e\u3057\u305f\u3002<\/p>\n<ul>\n<li>npm CLI\u306b\u3088\u308b\u3001\u30ed\u30b0\u30a4\u30f3\u304a\u3088\u3073\u30d1\u30d6\u30ea\u30c3\u30b7\u30e5\u30a8\u30af\u30b9\u30da\u30ea\u30a8\u30f3\u30b9\u306e\u52b9\u7387\u5316<\/li>\n<li>GitHub\u30a2\u30ab\u30a6\u30f3\u30c8\u3068Twitter\u30a2\u30ab\u30a6\u30f3\u30c8\u306enpm\u3078\u306e\u63a5\u7d9a<\/li>\n<li>npm\u306e\u3059\u3079\u3066\u306e\u30d1\u30c3\u30b1\u30fc\u30b8\u3078\u306e\u518d\u7f72\u540d\u306e\u5b8c\u4e86\u3001\u304a\u3088\u3073\u30d1\u30c3\u30b1\u30fc\u30b8\u306e\u6574\u5408\u6027\u3092\u76e3\u67fb\u3059\u308b\u65b0\u3057\u3044npm CLI\u30b3\u30de\u30f3\u30c9\u306e\u8ffd\u52a0<\/li>\n<li>\u30ed\u30b0\u30a4\u30f3\u304a\u3088\u3073\u30d1\u30d6\u30ea\u30c3\u30b7\u30e5\u306e\u52b9\u7387\u5316<\/li>\n<\/ul>\n<p>2FA\u306e\u5c0e\u5165\u306b\u3088\u308a\u3001\u30a2\u30ab\u30a6\u30f3\u30c8\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u306f\u5927\u5e45\u306b\u5411\u4e0a\u3057\u307e\u3059\u304c\u3001\u30e6\u30fc\u30b6\u30fc\u30a8\u30af\u30b9\u30da\u30ea\u30a8\u30f3\u30b9\u306f\u3042\u307e\u308a\u826f\u304f\u306a\u3044\u3082\u306e\u3067\u3042\u308b\u305f\u3081\u3001\u5229\u7528\u3057\u306a\u3044\u30e6\u30fc\u30b6\u30fc\u3082\u591a\u304f\u5b58\u5728\u3057\u307e\u3059\u3002\u305d\u3053\u3067\u3001GitHub\u306f\u6700\u8fd1\u3001\u30a8\u30f3\u30b8\u30cb\u30a2\u304c2FA\u3092\u5bb9\u6613\u306b\u5c0e\u5165\u3067\u304d\u308b\u3088\u3046\u306b\u3059\u308b\u305f\u3081\u306e\u3001npm\u30ec\u30b8\u30b9\u30c8\u30ea\u306b\u5bfe\u3059\u308b<a href=\"https:\/\/blog-github-com-develop.go-vip.co\/2022-05-10-enhanced-2fa-experience-for-your-npm-account\/\">\u3055\u307e\u3056\u307e\u306a\u6a5f\u80fd\u5f37\u5316<\/a>\u3092<a href=\"https:\/\/blog-github-com-develop.go-vip.co\/changelog\/2022-05-10-enhanced-2fa-experience-for-npm-accounts-public-beta\/\">\u30d1\u30d6\u30ea\u30c3\u30af\u30d9\u30fc\u30bf\u7248<\/a>\u3068\u3057\u3066\u30ea\u30ea\u30fc\u30b9\u3057\u307e\u3057\u305f\u3002\u65b0\u3057\u30442FA\u30a8\u30af\u30b9\u30da\u30ea\u30a8\u30f3\u30b9\u3092\u65e9\u671f\u306b\u5c0e\u5165\u3057\u305f\u30e6\u30fc\u30b6\u30fc\u304b\u3089\u3001npm CLI\u3092\u4f7f\u7528\u3057\u305f\u30ed\u30b0\u30a4\u30f3\u304a\u3088\u3073\u30d1\u30d6\u30ea\u30c3\u30b7\u30e5\u306e\u30d7\u30ed\u30bb\u30b9\u306b\u95a2\u3059\u308b\u30d5\u30a3\u30fc\u30c9\u30d0\u30c3\u30af\u304c\u5bc4\u305b\u3089\u308c\u3001\u3088\u308a\u591a\u304f\u306e\u6539\u5584\u304c\u5fc5\u8981\u3060\u3068\u308f\u304b\u308a\u307e\u3057\u305f\u3002\u5f53\u521d\u306e\u8a2d\u8a08\u3067\u306f\u3001npm 6\u3084\u305d\u306e\u4ed6\u306e\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u3068\u306e\u4e0b\u4f4d\u4e92\u63db\u6027\u3092\u6301\u3064\u3088\u3046\u306b\u3057\u305f\u3060\u3051\u3067\u306a\u304f\u3001Yarn\u30d7\u30ed\u30b8\u30a7\u30af\u30c8\u3067\u306f\u3001\u65b0\u3057\u3044\u30a8\u30af\u30b9\u30da\u30ea\u30a8\u30f3\u30b9\u306e\u30b5\u30dd\u30fc\u30c8\u3092<a href=\"https:\/\/github.com\/yarnpkg\/yarn\/commit\/5b2ac04316ff77d875de498f32d3088e0c9ce403\">10\u884c\u672a\u6e80\u306e\u30b3\u30fc\u30c9<\/a>\u3067Yarn1\u306b\u30d0\u30c3\u30af\u30dd\u30fc\u30c8\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3057\u305f\u3002<br \/>\n\u3053\u308c\u3089\u30d5\u30a3\u30fc\u30c9\u30d0\u30c3\u30af\u306b\u57fa\u3065\u304d\u3001\u3055\u3089\u306b\u6539\u5584\u3057\u305f\u30ed\u30b0\u30a4\u30f3\u304a\u3088\u3073\u30d1\u30d6\u30ea\u30c3\u30b7\u30e5\u6a5f\u80fd\u3092npm8.15.0\u3067\u5229\u7528\u3067\u304d\u308b\u3088\u3046\u306b\u306a\u308a\u307e\u3057\u305f\u3002\u6a5f\u80fd\u6539\u5584\u306b\u3088\u308b\u30e1\u30ea\u30c3\u30c8\u306f\u4ee5\u4e0b\u306e\u3068\u304a\u308a\u3067\u3059\u3002<\/p>\n<ul>\n<li>\u30ed\u30b0\u30a4\u30f3\u304a\u3088\u3073\u30d1\u30d6\u30ea\u30c3\u30b7\u30e5\u306e\u8a8d\u8a3c\u3092\u30d6\u30e9\u30a6\u30b6\u4e0a\u3067\u7ba1\u7406\u3002<\/li>\n<li>\u65e2\u5b58\u30bb\u30c3\u30b7\u30e7\u30f3\u3092\u4f7f\u7528\u3057\u3066\u30ed\u30b0\u30a4\u30f3\u3002\u65b0\u3057\u3044\u30bb\u30c3\u30b7\u30e7\u30f3\u3092\u4f5c\u6210\u3059\u308b\u6642\u306b\u3060\u3051\u30012\u756a\u76ee\u306e\u8981\u7d20\u307e\u305f\u306f\u30e1\u30fc\u30ebOTP\u691c\u8a3c\u304c\u6c42\u3081\u3089\u308c\u308b\u3002<\/li>\n<li>\u30d1\u30d6\u30ea\u30c3\u30b7\u30e5\u3067\u306f&amp;quot;remember me for 5 minutes (5\u5206\u9593\u8a18\u61b6\u3057\u3066\u304a\u304f)&amp;quot;\u6a5f\u80fd\u304c\u30b5\u30dd\u30fc\u30c8\u3055\u308c\u308b\u3088\u3046\u306b\u306a\u308a\u3001\u540c\u3058IP\u3068\u30a2\u30af\u30bb\u30b9\u30c8\u30fc\u30af\u30f3\u304b\u3089\u306e\u5f8c\u7d9a\u306e\u30d1\u30d6\u30ea\u30c3\u30b7\u30e5\u306b\u3064\u3044\u3066\u306f\u30012FA\u30d7\u30ed\u30f3\u30d7\u30c8\u30925\u5206\u9593\u56de\u907f\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u308b\u3002\u3053\u308c\u306f\u3001npm\u30ef\u30fc\u30af\u30b9\u30da\u30fc\u30b9\u304b\u3089\u30d1\u30d6\u30ea\u30c3\u30b7\u30e5\u3059\u308b\u5834\u5408\u306b\u7279\u306b\u4fbf\u5229\u3067\u3059\u3002\u73fe\u5728\u306f &#8211;auth-type=web \u30d5\u30e9\u30b0\u3092\u4f7f\u7528\u3057\u3066\u30aa\u30d7\u30c8\u30a4\u30f3\u3055\u308c\u3066\u304a\u308a\u3001npm 9\u3067\u306f\u30c7\u30d5\u30a9\u30eb\u30c8\u306e\u30a8\u30af\u30b9\u30da\u30ea\u30a8\u30f3\u30b9\u306b\u306a\u308a\u307e\u3059\u3002<\/li>\n<\/ul>\n<p>npm login &#8211;auth-type=web<br \/>\nnpm publish &#8211;auth-type=web<\/p>\n<p><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-3561 size-large\" src=\"https:\/\/blog-github-com-develop.go-vip.co\/jp\/wp-content\/uploads\/sites\/2\/2022\/08\/image1.gif?w=1024&#038;resize=1024%2C680\" alt=\"\" width=\"1024\" height=\"680\" \/><\/p>\n<p>\u3053\u3046\u3057\u305f\u6539\u5584\u306b\u3088\u308a\u3001\u30e6\u30fc\u30b6\u30fc\u306f\u81ea\u5206\u306e\u30a2\u30ab\u30a6\u30f3\u30c8\u3092\u3088\u308a\u7c21\u5358\u306b\u4fdd\u8b77\u3067\u304d\u308b\u3088\u3046\u306b\u306a\u308a\u307e\u3059\u3002\u5b89\u5168\u306a\u30a2\u30ab\u30a6\u30f3\u30c8\u306f\u3001\u5b89\u5168\u306a\u30a8\u30b3\u30b7\u30b9\u30c6\u30e0\u3092\u5b9f\u73fe\u3059\u308b\u305f\u3081\u306e<a href=\"https:\/\/github.com\/yarnpkg\/yarn\/commit\/5b2ac04316ff77d875de498f32d3088e0c9ce403\">\u7b2c\u4e00\u6b69<\/a>\u3067\u3059\u3002npm\u3067\u306e2FA\u306e\u8a73\u7d30\u306b\u3064\u3044\u3066\u306f\u3001<a href=\"https:\/\/docs.npmjs.com\/about-two-factor-authentication\">\u3053\u3061\u3089\u306e\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8<\/a>\u3092\u3054\u78ba\u8a8d\u304f\u3060\u3055\u3044\u3002<\/p>\n<h3 id=\"github%e3%82%a2%e3%82%ab%e3%82%a6%e3%83%b3%e3%83%88%e3%81%a8twitter%e3%82%a2%e3%82%ab%e3%82%a6%e3%83%b3%e3%83%88%e3%81%aenpm%e3%81%b8%e3%81%ae%e6%8e%a5%e7%b6%9a\">GitHub\u30a2\u30ab\u30a6\u30f3\u30c8\u3068Twitter\u30a2\u30ab\u30a6\u30f3\u30c8\u306enpm\u3078\u306e\u63a5\u7d9a<a href=\"#github%e3%82%a2%e3%82%ab%e3%82%a6%e3%83%b3%e3%83%88%e3%81%a8twitter%e3%82%a2%e3%82%ab%e3%82%a6%e3%83%b3%e3%83%88%e3%81%aenpm%e3%81%b8%e3%81%ae%e6%8e%a5%e7%b6%9a\" class=\"heading-link\" aria-label=\"GitHub\u30a2\u30ab\u30a6\u30f3\u30c8\u3068Twitter\u30a2\u30ab\u30a6\u30f3\u30c8\u306enpm\u3078\u306e\u63a5\u7d9a\" data-anchorjs-icon=\"#\" style=\"padding-left: 0.375em;\"><\/a><\/h3>\n<p><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-3565 size-large\" src=\"https:\/\/blog-github-com-develop.go-vip.co\/jp\/wp-content\/uploads\/sites\/2\/2022\/08\/connect-github.jpg?w=545&#038;resize=545%2C302\" alt=\"\" width=\"545\" height=\"302\" srcset=\"https:\/\/blog-github-com-develop.go-vip.co\/jp\/wp-content\/uploads\/sites\/2\/2022\/08\/connect-github.jpg?w=545 545w, https:\/\/blog-github-com-develop.go-vip.co\/jp\/wp-content\/uploads\/sites\/2\/2022\/08\/connect-github.jpg?w=300 300w\" sizes=\"auto, (max-width: 545px) 100vw, 545px\" \/><\/p>\n<p>npm\u30a2\u30ab\u30a6\u30f3\u30c8\u304c\u5229\u7528\u53ef\u80fd\u306a\u72b6\u614b\u3067\u3042\u308c\u3070\u3001\u307b\u3068\u3093\u3069\u306e\u5834\u5408\u3001GitHub\u306e\u30cf\u30f3\u30c9\u30eb\u3068Twitter\u306e\u30cf\u30f3\u30c9\u30eb\u3092npm\u30d7\u30ed\u30d5\u30a1\u30a4\u30eb\u306b\u542b\u3081\u308b\u3053\u3068\u304c\u3067\u304d\u3066\u3044\u307e\u3057\u305f\u3002\u3053\u308c\u306f\u3001npm\u30a2\u30ab\u30a6\u30f3\u30c8\u306eID\u3092\u4ed6\u306e\u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0\u306eID\u306b\u63a5\u7d9a\u3059\u308b\u969b\u306b\u5f79\u7acb\u3063\u3066\u3044\u307e\u3057\u305f\u304c\u3001\u3053\u306e\u30c7\u30fc\u30bf\u306f\u5f93\u6765\u3001\u8a8d\u8a3c\u3082\u691c\u8a3c\u3082\u3055\u308c\u3066\u3044\u306a\u3044\u81ea\u7531\u5f62\u5f0f\u306e\u30c6\u30ad\u30b9\u30c8\u30d5\u30a3\u30fc\u30eb\u30c9\u3067\u3057\u305f\u3002<\/p>\n<p>\u305d\u306e\u305f\u3081\u3001npm\u306e\u30a2\u30ab\u30a6\u30f3\u30c8\u3092GitHub\u30a2\u30ab\u30a6\u30f3\u30c8\u3084Twitter\u30a2\u30ab\u30a6\u30f3\u30c8\u306b\u30ea\u30f3\u30af\u3055\u305b\u308b\u6a5f\u80fd\u306e\u63d0\u4f9b\u3092\u958b\u59cb\u3057\u307e\u3057\u305f\u3002\u3053\u308c\u3089\u306e\u30a2\u30ab\u30a6\u30f3\u30c8\u3068\u306e\u30ea\u30f3\u30af\u306f\u3001GitHub\u3068Twitter\u306e\u4e21\u65b9\u3068\u516c\u5f0f\u306b\u7d71\u5408\u3059\u308b\u3053\u3068\u3067\u5b9f\u884c\u3055\u308c\u3001\u7d71\u5408\u5f8c\u306f\u691c\u8a3c\u6e08\u307f\u30a2\u30ab\u30a6\u30f3\u30c8\u30c7\u30fc\u30bf\u304cnpm\u30d7\u30ed\u30d5\u30a1\u30a4\u30eb\u306b\u5fc5\u305a\u542b\u307e\u308c\u308b\u3088\u3046\u306b\u306a\u308a\u307e\u3059\u3002\u305d\u308c\u4ee5\u524d\u306e\u672a\u691c\u8a3c\u306eGitHub\u30c7\u30fc\u30bf\u307e\u305f\u306fTwitter\u30c7\u30fc\u30bf\u306f\u30d1\u30d6\u30ea\u30c3\u30af\u30e6\u30fc\u30b6\u30fc\u30d7\u30ed\u30d5\u30a3\u30fc\u30eb\u306b\u8868\u793a\u3055\u308c\u306a\u304f\u306a\u308a\u307e\u3059\u304c\u3001\u958b\u767a\u8005\u306fID\u3092\u76e3\u67fb\u3057\u3066\u3001\u30a2\u30ab\u30a6\u30f3\u30c8\u304c\u672c\u4eba\u3067\u3042\u308b\u3068\u4fe1\u983c\u3067\u304d\u308b\u3088\u3046\u306b\u3059\u308b\u3053\u3068\u304c\u53ef\u80fd\u3067\u3059\u3002\u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0\u5168\u4f53\u3067ID\u9593\u306e\u30ea\u30f3\u30af\u3092\u691c\u8a3c\u6e08\u307f\u306b\u3059\u308b\u3053\u3068\u3067\u3001\u30a2\u30ab\u30a6\u30f3\u30c8\u30ea\u30ab\u30d0\u30ea\u6a5f\u80fd\u304c\u5927\u5e45\u306b\u5411\u4e0a\u3057\u307e\u3059\u3002\u3053\u306e\u65b0\u3057\u3044\u691c\u8a3c\u6e08\u307f\u30c7\u30fc\u30bf\u306f\u3001\u30a2\u30ab\u30a6\u30f3\u30c8\u30ea\u30ab\u30d0\u30ea\u306e\u4e00\u90e8\u3068\u3057\u3066ID\u691c\u8a3c\u3092\u81ea\u52d5\u5316\u3059\u308b\u305f\u3081\u306e\u57fa\u76e4\u3068\u306a\u3063\u3066\u3044\u307e\u3059\u3002\u3053\u308c\u307e\u3067\u306e\u30ec\u30ac\u30b7\u30fc\u30c7\u30fc\u30bf\u306f\u5f90\u3005\u306b\u5ec3\u6b62\u3057\u3066\u3044\u304f\u4e88\u5b9a\u3067\u3059\u304c\u3001\u30e6\u30fc\u30b6\u30fc\u306e\u30a2\u30ab\u30a6\u30f3\u30c8\u304c\u30ed\u30c3\u30af\u3055\u308c\u306a\u3044\u3088\u3046\u306b\u3001\u5f53\u9762\u306e\u9593\u306f\u5f15\u304d\u7d9a\u304d\u3053\u306e\u30c7\u30fc\u30bf\u3092\u4f7f\u7528\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002<\/p>\n<h3 id=\"npm-audit-signatures-npm-audit-signatures-%e3%82%92%e4%bd%bf%e7%94%a8%e3%81%97%e3%81%a6%e3%80%81%e3%83%91%e3%83%83%e3%82%b1%e3%83%bc%e3%82%b8%e3%82%92%e3%83%ad%e3%83%bc%e3%82%ab%e3%83%ab%e3%81%a7\">npm audit signatures npm audit signatures \u3092\u4f7f\u7528\u3057\u3066\u3001\u30d1\u30c3\u30b1\u30fc\u30b8\u3092\u30ed\u30fc\u30ab\u30eb\u3067\u691c\u8a3c\u53ef\u80fd<a href=\"#npm-audit-signatures-npm-audit-signatures-%e3%82%92%e4%bd%bf%e7%94%a8%e3%81%97%e3%81%a6%e3%80%81%e3%83%91%e3%83%83%e3%82%b1%e3%83%bc%e3%82%b8%e3%82%92%e3%83%ad%e3%83%bc%e3%82%ab%e3%83%ab%e3%81%a7\" class=\"heading-link\" aria-label=\"npm audit signatures npm audit signatures \u3092\u4f7f\u7528\u3057\u3066\u3001\u30d1\u30c3\u30b1\u30fc\u30b8\u3092\u30ed\u30fc\u30ab\u30eb\u3067\u691c\u8a3c\u53ef\u80fd\" data-anchorjs-icon=\"#\" style=\"padding-left: 0.375em;\"><\/a><\/h3>\n<p>\u4eca\u65e5\u307e\u3067\u3001npm\u30e6\u30fc\u30b6\u30fc\u304cnpm\u30d1\u30c3\u30b1\u30fc\u30b8\u306e\u7f72\u540d\u3092\u691c\u8a3c\u3059\u308b\u305f\u3081\u306b\u3001<a href=\"https:\/\/docs.npmjs.com\/verifying-the-pgp-signature-for-a-package-from-the-npm-public-registry\">\u591a\u6bb5\u968e\u306e\u30d7\u30ed\u30bb\u30b9<\/a>\u304c\u5fc5\u8981\u3067\u3057\u305f\u3002\u3053\u306e<a href=\"https:\/\/en.wikipedia.org\/wiki\/Pretty_Good_Privacy\">PGP<\/a>\u30d9\u30fc\u30b9\u306e\u30d7\u30ed\u30bb\u30b9\u306f\u8907\u96d1\u3067\u3042\u308b\u3060\u3051\u3067\u306a\u304f\u3001\u6697\u53f7\u5316\u30c4\u30fc\u30eb\u306b\u95a2\u3059\u308b\u77e5\u8b58\u304c\u5fc5\u8981\u3067\u3042\u3063\u305f\u305f\u3081\u3001\u958b\u767a\u8005\u30a8\u30af\u30b9\u30da\u30ea\u30a8\u30f3\u30b9\u306e\u4f4e\u4e0b\u306b\u3064\u306a\u304c\u3063\u3066\u3044\u307e\u3057\u305f\u3002\u3053\u306e\u5f93\u6765\u578b\u306e\u30d7\u30ed\u30bb\u30b9\u3092\u5229\u7528\u3057\u3066\u3044\u308b\u5834\u5408\u306f\u3001\u3059\u3050\u306b\u65b0\u3057\u3044<span style=\"font-weight: 400;\">&#8220;audit signatures&#8221;<\/span>\u30b3\u30de\u30f3\u30c9\u3092\u4f7f\u3044\u59cb\u3081\u308b\u3053\u3068\u3092\u304a\u3059\u3059\u3081\u3057\u307e\u3059\u3002PGP\u30ad\u30fc\u306f2023\u5e74\u521d\u3081\u306b\u671f\u9650\u304c\u5207\u308c\u308b\u3053\u3068\u306b\u306a\u3063\u3066\u3044\u307e\u3059\u3002\u8a73\u7d30\u306f\u5f8c\u65e5\u304a\u77e5\u3089\u305b\u3057\u307e\u3059\u3002<\/p>\n<p>GitHub\u3067\u306f\u6700\u8fd1\u3001\u5b89\u5168\u306a<a href=\"https:\/\/en.wikipedia.org\/wiki\/Elliptic_Curve_Digital_Signature_Algorithm\">ECDSA<\/a>\u30a2\u30eb\u30b4\u30ea\u30ba\u30e0\u3092\u5229\u7528\u3057\u3001<a href=\"https:\/\/en.wikipedia.org\/wiki\/Hardware_security_module\">HSM<\/a>\u3067\u30ad\u30fc\u3092\u7ba1\u7406\u3059\u308b\u65b0\u3057\u3044\u7f72\u540d\u3067\u3001\u3059\u3079\u3066\u306enpm\u30d1\u30c3\u30b1\u30fc\u30b8\u3092\u518d\u7f72\u540d\u3059\u308b\u4f5c\u696d\u3092\u958b\u59cb\u3057\u307e\u3057\u305f\u3002\u3053\u308c\u306b\u3088\u308a\u3001\u3053\u306e\u7f72\u540d\u3092\u5229\u7528\u3057\u3066\u3001npm\u304b\u3089\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3059\u308b\u30d1\u30c3\u30b1\u30fc\u30b8\u306e\u6574\u5408\u6027\u3092\u691c\u8a3c\u3067\u304d\u308b\u3088\u3046\u306b\u306a\u308a\u307e\u3057\u305f\u3002<\/p>\n<p>npm CLI\u30d0\u30fc\u30b8\u30e7\u30f38.13.0\u4ee5\u964d\u3067\u65b0\u3057\u3044audit signatures\u30b3\u30de\u30f3\u30c9\u3092\u5c0e\u5165\u3057\u307e\u3057\u305f\u3002<\/p>\n<p><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-3566 size-large\" src=\"https:\/\/blog-github-com-develop.go-vip.co\/jp\/wp-content\/uploads\/sites\/2\/2022\/08\/image3.gif?w=800&#038;resize=800%2C342\" alt=\"\" width=\"800\" height=\"342\" \/><\/p>\n<p style=\"text-align: center;\">audit signature\u306b\u3088\u308b\u691c\u8a3c\u306e\u6210\u529f\u4f8b<\/p>\n<p>audit signature \u3092\u5b9f\u884c\u3057\u305fGitHub Actions\u30ef\u30fc\u30af\u30d5\u30ed\u30fc\u306e\u30b5\u30f3\u30d7\u30eb\u3092\u4e0b\u306b\u793a\u3057\u307e\u3059\u3002<\/p>\n<p><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-3572 size-large\" src=\"https:\/\/blog-github-com-develop.go-vip.co\/jp\/wp-content\/uploads\/sites\/2\/2022\/08\/\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8-2022-08-15-14.21.47.png?w=701&#038;resize=701%2C588\" alt=\"\" width=\"701\" height=\"588\" srcset=\"https:\/\/blog-github-com-develop.go-vip.co\/jp\/wp-content\/uploads\/sites\/2\/2022\/08\/\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8-2022-08-15-14.21.47.png?w=701 701w, https:\/\/blog-github-com-develop.go-vip.co\/jp\/wp-content\/uploads\/sites\/2\/2022\/08\/\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8-2022-08-15-14.21.47.png?w=300 300w\" sizes=\"auto, (max-width: 701px) 100vw, 701px\" \/><\/p>\n<h3 id=\"\"><a href=\"#\" class=\"heading-link\" aria-label=\"\" data-anchorjs-icon=\"#\" style=\"padding-left: 0.375em;\"><\/a><\/h3>\n<h3 id=\"\"><a href=\"#\" class=\"heading-link\" aria-label=\"\" data-anchorjs-icon=\"#\" style=\"padding-left: 0.375em;\"><\/a><\/h3>\n<h3 id=\"%e4%bb%8a%e5%be%8c%e3%81%ae%e5%b1%95%e6%9c%9b\">\u4eca\u5f8c\u306e\u5c55\u671b<a href=\"#%e4%bb%8a%e5%be%8c%e3%81%ae%e5%b1%95%e6%9c%9b\" class=\"heading-link\" aria-label=\"\u4eca\u5f8c\u306e\u5c55\u671b\" data-anchorjs-icon=\"#\" style=\"padding-left: 0.375em;\"><\/a><\/h3>\n<p>\u79c1\u305f\u3061\u306e\u4e3b\u306a\u76ee\u6a19\u306f\u3001\u5f15\u304d\u7d9a\u304dnpm\u30ec\u30b8\u30b9\u30c8\u30ea\u3092\u4fdd\u8b77\u3059\u308b\u3053\u3068\u3067\u3059\u3002\u6b21\u306e\u4e3b\u8981\u306a\u30de\u30a4\u30eb\u30b9\u30c8\u30fc\u30f3\u306f\u3001\u5f71\u97ff\u529b\u306e\u5927\u304d\u3044\u3059\u3079\u3066\u306e\u30a2\u30ab\u30a6\u30f3\u30c8(\u4f8b\uff1a\u6bce\u9031\u306e\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u6570\u304c100\u4e07\u56de\u3092\u8d85\u3048\u308b\u304b\u3001500\u4ee5\u4e0a\u306e\u4f9d\u5b58\u95a2\u4fc2\u3092\u6301\u3064\u30d1\u30c3\u30b1\u30fc\u30b8\u3092\u7ba1\u7406\u3059\u308b\u30a2\u30ab\u30a6\u30f3\u30c8)\u306b\u5bfe\u3057\u30662FA\u3092\u9069\u7528\u3057\u30012\u756a\u76ee\u306e\u8981\u7d20\u306e\u5c0e\u5165\u3092\u6c42\u3081\u308b\u30a2\u30ab\u30a6\u30f3\u30c8\u6570\u30923\u500d\u306b\u5897\u3084\u3059\u3053\u3068\u3067\u3059\u30022FA\u306e\u9069\u7528\u306b\u5148\u7acb\u3063\u3066\u3001<br \/>\n\u8ffd\u52a0\u306eID\u691c\u8a3c\u5f62\u5f0f\u3092\u5c0e\u5165\u3057\u305f\u308a\u3001\u30d7\u30ed\u30bb\u30b9\u3092\u53ef\u80fd\u306a\u9650\u308a\u81ea\u52d5\u5316\u3059\u308b\u306a\u3069\u3001\u30a2\u30ab\u30a6\u30f3\u30c8\u30ea\u30ab\u30d0\u30ea\u30d7\u30ed\u30bb\u30b9\u3092\u3055\u3089\u306b\u6539\u5584\u3057\u3066\u3044\u304f\u4e88\u5b9a\u3067\u3059\u3002<\/p>\n<p>\u3053\u308c\u3089\u306e\u6a5f\u80fd\u306e\u8a73\u7d30\u306b\u3064\u3044\u3066\u306f\u3001\u6b21\u306e\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u3067\u3054\u78ba\u8a8d\u3044\u305f\u3060\u3051\u307e\u3059.<\/p>\n<ul>\n<li>\u00a0<a href=\"https:\/\/docs.npmjs.com\/configuring-two-factor-authentication\">2\u8981\u7d20\u8a8d\u8a3c\u306e\u8a2d\u5b9a<\/a><\/li>\n<li>\u00a0<a href=\"https:\/\/docs.npmjs.com\/about-two-factor-authentication\">2\u8981\u7d20\u8a8d\u8a3c\u306b\u3064\u3044\u3066<\/a><\/li>\n<li><a href=\"https:\/\/docs.npmjs.com\/managing-your-profile-settings\">\u30d7\u30ed\u30d5\u30a3\u30fc\u30eb\u8a2d\u5b9a\u306e\u7ba1\u7406<\/a><\/li>\n<li><a href=\"https:\/\/docs.npmjs.com\/about-registry-signatures\">\u30ec\u30b8\u30b9\u30c8\u30ea\u7f72\u540d\u306b\u3064\u3044\u3066<\/a><\/li>\n<li><a href=\"https:\/\/docs.npmjs.com\/verifying-registry-signatures\">\u30ec\u30b8\u30b9\u30c8\u30ea\u7f72\u540d\u306e\u691c\u8a3c\u65b9\u6cd5<\/a><\/li>\n<\/ul>\n<p>\u8cea\u554f\u3084\u30b3\u30e1\u30f3\u30c8\u306b\u3064\u3044\u3066\u306f\u3001<a href=\"https:\/\/github.com\/npm\/feedback\">\u30d5\u30a3\u30fc\u30c9\u30d0\u30c3\u30af\u30ea\u30dd\u30b8\u30c8\u30ea<\/a>\u3067\u30c7\u30a3\u30b9\u30ab\u30c3\u30b7\u30e7\u30f3\u3092\u958b\u3044\u3066\u304a\u77e5\u305b\u304f\u3060\u3055\u3044\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>npm CLI\u3092\u4f7f\u7528\u3057\u305f\u30ed\u30b0\u30a4\u30f3\u304a\u3088\u3073\u30d1\u30d6\u30ea\u30c3\u30b7\u30e5\u306e\u6539\u5584\u3001GitHub\u30a2\u30ab\u30a6\u30f3\u30c8\u3068Twitter\u30a2\u30ab\u30a6\u30f3\u30c8\u306e\u63a5\u7d9a\u3001npm\u3067\u306e\u30d1\u30c3\u30b1\u30fc\u30b8\u306e\u6574\u5408\u6027\u3092\u691c\u8a3c\u3059\u308b\u65b0\u3057\u3044CLI\u30b3\u30de\u30f3\u30c9\u306a\u3069\u3001npm\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u3092\u5f37\u5316\u3057\u307e\u3057\u305f\u3002<\/p>\n","protected":false},"author":2027,"featured_media":3576,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_crdt_document":"","jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"_wpas_customize_per_network":false},"categories":[31,33,9,36],"tags":[],"coauthors":[110,109],"class_list":["post-3556","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-engineering","category-opensource","category-product","category-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.3 (Yoast SEO v27.3) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>npm\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u6a5f\u80fd\u3092\u3055\u3089\u306b\u5f37\u5316 - GitHub\u30d6\u30ed\u30b0<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/blog-github-com-develop.go-vip.co\/jp\/2022-08-15-introducing-even-more-security-enhancements-to-npm\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"npm\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u6a5f\u80fd\u3092\u3055\u3089\u306b\u5f37\u5316\" \/>\n<meta property=\"og:description\" content=\"npm CLI\u3092\u4f7f\u7528\u3057\u305f\u30ed\u30b0\u30a4\u30f3\u304a\u3088\u3073\u30d1\u30d6\u30ea\u30c3\u30b7\u30e5\u306e\u6539\u5584\u3001GitHub\u30a2\u30ab\u30a6\u30f3\u30c8\u3068Twitter\u30a2\u30ab\u30a6\u30f3\u30c8\u306e\u63a5\u7d9a\u3001npm\u3067\u306e\u30d1\u30c3\u30b1\u30fc\u30b8\u306e\u6574\u5408\u6027\u3092\u691c\u8a3c\u3059\u308b\u65b0\u3057\u3044CLI\u30b3\u30de\u30f3\u30c9\u306a\u3069\u3001npm\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u3092\u5f37\u5316\u3057\u307e\u3057\u305f\u3002\" \/>\n<meta property=\"og:url\" content=\"https:\/\/blog-github-com-develop.go-vip.co\/jp\/2022-08-15-introducing-even-more-security-enhancements-to-npm\/\" \/>\n<meta property=\"og:site_name\" content=\"GitHub\u30d6\u30ed\u30b0\" \/>\n<meta property=\"article:published_time\" content=\"2022-08-15T05:45:23+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-08-15T06:21:27+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/blog-github-com-develop.go-vip.co\/jp\/wp-content\/uploads\/sites\/2\/2022\/08\/npm-github.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Monish Mohan, Myles Borins\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Monish Mohan, Myles Borins\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/blog-github-com-develop.go-vip.co\\\/jp\\\/2022-08-15-introducing-even-more-security-enhancements-to-npm\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/blog-github-com-develop.go-vip.co\\\/jp\\\/2022-08-15-introducing-even-more-security-enhancements-to-npm\\\/\"},\"author\":{\"name\":\"Monish Mohan\",\"@id\":\"https:\\\/\\\/blog-github-com-develop.go-vip.co\\\/jp\\\/#\\\/schema\\\/person\\\/7d3e9734b09cf8677c96c95b379061ce\"},\"headline\":\"npm\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u6a5f\u80fd\u3092\u3055\u3089\u306b\u5f37\u5316\",\"datePublished\":\"2022-08-15T05:45:23+00:00\",\"dateModified\":\"2022-08-15T06:21:27+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/blog-github-com-develop.go-vip.co\\\/jp\\\/2022-08-15-introducing-even-more-security-enhancements-to-npm\\\/\"},\"wordCount\":110,\"image\":{\"@id\":\"https:\\\/\\\/blog-github-com-develop.go-vip.co\\\/jp\\\/2022-08-15-introducing-even-more-security-enhancements-to-npm\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/blog-github-com-develop.go-vip.co\\\/jp\\\/wp-content\\\/uploads\\\/sites\\\/2\\\/2022\\\/08\\\/npm-github.png?fit=1200%2C630\",\"articleSection\":[\"Engineering\",\"Opensource\",\"Product\",\"Security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/blog-github-com-develop.go-vip.co\\\/jp\\\/2022-08-15-introducing-even-more-security-enhancements-to-npm\\\/\",\"url\":\"https:\\\/\\\/blog-github-com-develop.go-vip.co\\\/jp\\\/2022-08-15-introducing-even-more-security-enhancements-to-npm\\\/\",\"name\":\"npm\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u6a5f\u80fd\u3092\u3055\u3089\u306b\u5f37\u5316 - GitHub\u30d6\u30ed\u30b0\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/blog-github-com-develop.go-vip.co\\\/jp\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/blog-github-com-develop.go-vip.co\\\/jp\\\/2022-08-15-introducing-even-more-security-enhancements-to-npm\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/blog-github-com-develop.go-vip.co\\\/jp\\\/2022-08-15-introducing-even-more-security-enhancements-to-npm\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/blog-github-com-develop.go-vip.co\\\/jp\\\/wp-content\\\/uploads\\\/sites\\\/2\\\/2022\\\/08\\\/npm-github.png?fit=1200%2C630\",\"datePublished\":\"2022-08-15T05:45:23+00:00\",\"dateModified\":\"2022-08-15T06:21:27+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/blog-github-com-develop.go-vip.co\\\/jp\\\/#\\\/schema\\\/person\\\/7d3e9734b09cf8677c96c95b379061ce\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/blog-github-com-develop.go-vip.co\\\/jp\\\/2022-08-15-introducing-even-more-security-enhancements-to-npm\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/blog-github-com-develop.go-vip.co\\\/jp\\\/2022-08-15-introducing-even-more-security-enhancements-to-npm\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/blog-github-com-develop.go-vip.co\\\/jp\\\/2022-08-15-introducing-even-more-security-enhancements-to-npm\\\/#primaryimage\",\"url\":\"https:\\\/\\\/blog-github-com-develop.go-vip.co\\\/jp\\\/wp-content\\\/uploads\\\/sites\\\/2\\\/2022\\\/08\\\/npm-github.png?fit=1200%2C630\",\"contentUrl\":\"https:\\\/\\\/blog-github-com-develop.go-vip.co\\\/jp\\\/wp-content\\\/uploads\\\/sites\\\/2\\\/2022\\\/08\\\/npm-github.png?fit=1200%2C630\",\"width\":1200,\"height\":630},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/blog-github-com-develop.go-vip.co\\\/jp\\\/2022-08-15-introducing-even-more-security-enhancements-to-npm\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/blog-github-com-develop.go-vip.co\\\/jp\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"npm\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u6a5f\u80fd\u3092\u3055\u3089\u306b\u5f37\u5316\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/blog-github-com-develop.go-vip.co\\\/jp\\\/#website\",\"url\":\"https:\\\/\\\/blog-github-com-develop.go-vip.co\\\/jp\\\/\",\"name\":\"GitHub\u30d6\u30ed\u30b0\",\"description\":\"\u88fd\u54c1\u30a2\u30c3\u30d7\u30c7\u30fc\u30c8\u3084\u958b\u767a\u306b\u95a2\u3059\u308b\u30a2\u30a4\u30c7\u30a3\u30a2\u3084\u30a4\u30f3\u30b9\u30d4\u30ec\u30fc\u30b7\u30e7\u30f3\u306a\u3069\u3001\u30a8\u30f3\u30b8\u30cb\u30a2\u306e\u7686\u3055\u3093\u306b\u5f79\u7acb\u3064\u60c5\u5831\u3092\u767a\u4fe1\u3057\u307e\u3059\u3002\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/blog-github-com-develop.go-vip.co\\\/jp\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/blog-github-com-develop.go-vip.co\\\/jp\\\/#\\\/schema\\\/person\\\/7d3e9734b09cf8677c96c95b379061ce\",\"name\":\"Monish Mohan\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/bfba285772a1e72cd10db5f50f7331968baaca60786aaaf0f24ddc70cd602d93?s=96&d=mm&r=gce7f856f17293c730fd457ddef5795b0\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/bfba285772a1e72cd10db5f50f7331968baaca60786aaaf0f24ddc70cd602d93?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/bfba285772a1e72cd10db5f50f7331968baaca60786aaaf0f24ddc70cd602d93?s=96&d=mm&r=g\",\"caption\":\"Monish Mohan\"},\"url\":\"https:\\\/\\\/blog-github-com-develop.go-vip.co\\\/jp\\\/author\\\/monishcm\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"npm\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u6a5f\u80fd\u3092\u3055\u3089\u306b\u5f37\u5316 - GitHub\u30d6\u30ed\u30b0","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/blog-github-com-develop.go-vip.co\/jp\/2022-08-15-introducing-even-more-security-enhancements-to-npm\/","og_locale":"en_US","og_type":"article","og_title":"npm\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u6a5f\u80fd\u3092\u3055\u3089\u306b\u5f37\u5316","og_description":"npm CLI\u3092\u4f7f\u7528\u3057\u305f\u30ed\u30b0\u30a4\u30f3\u304a\u3088\u3073\u30d1\u30d6\u30ea\u30c3\u30b7\u30e5\u306e\u6539\u5584\u3001GitHub\u30a2\u30ab\u30a6\u30f3\u30c8\u3068Twitter\u30a2\u30ab\u30a6\u30f3\u30c8\u306e\u63a5\u7d9a\u3001npm\u3067\u306e\u30d1\u30c3\u30b1\u30fc\u30b8\u306e\u6574\u5408\u6027\u3092\u691c\u8a3c\u3059\u308b\u65b0\u3057\u3044CLI\u30b3\u30de\u30f3\u30c9\u306a\u3069\u3001npm\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u3092\u5f37\u5316\u3057\u307e\u3057\u305f\u3002","og_url":"https:\/\/blog-github-com-develop.go-vip.co\/jp\/2022-08-15-introducing-even-more-security-enhancements-to-npm\/","og_site_name":"GitHub\u30d6\u30ed\u30b0","article_published_time":"2022-08-15T05:45:23+00:00","article_modified_time":"2022-08-15T06:21:27+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/blog-github-com-develop.go-vip.co\/jp\/wp-content\/uploads\/sites\/2\/2022\/08\/npm-github.png","type":"image\/png"}],"author":"Monish Mohan, Myles Borins","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Monish Mohan, Myles Borins","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/blog-github-com-develop.go-vip.co\/jp\/2022-08-15-introducing-even-more-security-enhancements-to-npm\/#article","isPartOf":{"@id":"https:\/\/blog-github-com-develop.go-vip.co\/jp\/2022-08-15-introducing-even-more-security-enhancements-to-npm\/"},"author":{"name":"Monish Mohan","@id":"https:\/\/blog-github-com-develop.go-vip.co\/jp\/#\/schema\/person\/7d3e9734b09cf8677c96c95b379061ce"},"headline":"npm\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u6a5f\u80fd\u3092\u3055\u3089\u306b\u5f37\u5316","datePublished":"2022-08-15T05:45:23+00:00","dateModified":"2022-08-15T06:21:27+00:00","mainEntityOfPage":{"@id":"https:\/\/blog-github-com-develop.go-vip.co\/jp\/2022-08-15-introducing-even-more-security-enhancements-to-npm\/"},"wordCount":110,"image":{"@id":"https:\/\/blog-github-com-develop.go-vip.co\/jp\/2022-08-15-introducing-even-more-security-enhancements-to-npm\/#primaryimage"},"thumbnailUrl":"https:\/\/blog-github-com-develop.go-vip.co\/jp\/wp-content\/uploads\/sites\/2\/2022\/08\/npm-github.png?fit=1200%2C630","articleSection":["Engineering","Opensource","Product","Security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/blog-github-com-develop.go-vip.co\/jp\/2022-08-15-introducing-even-more-security-enhancements-to-npm\/","url":"https:\/\/blog-github-com-develop.go-vip.co\/jp\/2022-08-15-introducing-even-more-security-enhancements-to-npm\/","name":"npm\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u6a5f\u80fd\u3092\u3055\u3089\u306b\u5f37\u5316 - GitHub\u30d6\u30ed\u30b0","isPartOf":{"@id":"https:\/\/blog-github-com-develop.go-vip.co\/jp\/#website"},"primaryImageOfPage":{"@id":"https:\/\/blog-github-com-develop.go-vip.co\/jp\/2022-08-15-introducing-even-more-security-enhancements-to-npm\/#primaryimage"},"image":{"@id":"https:\/\/blog-github-com-develop.go-vip.co\/jp\/2022-08-15-introducing-even-more-security-enhancements-to-npm\/#primaryimage"},"thumbnailUrl":"https:\/\/blog-github-com-develop.go-vip.co\/jp\/wp-content\/uploads\/sites\/2\/2022\/08\/npm-github.png?fit=1200%2C630","datePublished":"2022-08-15T05:45:23+00:00","dateModified":"2022-08-15T06:21:27+00:00","author":{"@id":"https:\/\/blog-github-com-develop.go-vip.co\/jp\/#\/schema\/person\/7d3e9734b09cf8677c96c95b379061ce"},"breadcrumb":{"@id":"https:\/\/blog-github-com-develop.go-vip.co\/jp\/2022-08-15-introducing-even-more-security-enhancements-to-npm\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/blog-github-com-develop.go-vip.co\/jp\/2022-08-15-introducing-even-more-security-enhancements-to-npm\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog-github-com-develop.go-vip.co\/jp\/2022-08-15-introducing-even-more-security-enhancements-to-npm\/#primaryimage","url":"https:\/\/blog-github-com-develop.go-vip.co\/jp\/wp-content\/uploads\/sites\/2\/2022\/08\/npm-github.png?fit=1200%2C630","contentUrl":"https:\/\/blog-github-com-develop.go-vip.co\/jp\/wp-content\/uploads\/sites\/2\/2022\/08\/npm-github.png?fit=1200%2C630","width":1200,"height":630},{"@type":"BreadcrumbList","@id":"https:\/\/blog-github-com-develop.go-vip.co\/jp\/2022-08-15-introducing-even-more-security-enhancements-to-npm\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/blog-github-com-develop.go-vip.co\/jp\/"},{"@type":"ListItem","position":2,"name":"npm\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u6a5f\u80fd\u3092\u3055\u3089\u306b\u5f37\u5316"}]},{"@type":"WebSite","@id":"https:\/\/blog-github-com-develop.go-vip.co\/jp\/#website","url":"https:\/\/blog-github-com-develop.go-vip.co\/jp\/","name":"GitHub\u30d6\u30ed\u30b0","description":"\u88fd\u54c1\u30a2\u30c3\u30d7\u30c7\u30fc\u30c8\u3084\u958b\u767a\u306b\u95a2\u3059\u308b\u30a2\u30a4\u30c7\u30a3\u30a2\u3084\u30a4\u30f3\u30b9\u30d4\u30ec\u30fc\u30b7\u30e7\u30f3\u306a\u3069\u3001\u30a8\u30f3\u30b8\u30cb\u30a2\u306e\u7686\u3055\u3093\u306b\u5f79\u7acb\u3064\u60c5\u5831\u3092\u767a\u4fe1\u3057\u307e\u3059\u3002","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/blog-github-com-develop.go-vip.co\/jp\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/blog-github-com-develop.go-vip.co\/jp\/#\/schema\/person\/7d3e9734b09cf8677c96c95b379061ce","name":"Monish Mohan","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/bfba285772a1e72cd10db5f50f7331968baaca60786aaaf0f24ddc70cd602d93?s=96&d=mm&r=gce7f856f17293c730fd457ddef5795b0","url":"https:\/\/secure.gravatar.com\/avatar\/bfba285772a1e72cd10db5f50f7331968baaca60786aaaf0f24ddc70cd602d93?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/bfba285772a1e72cd10db5f50f7331968baaca60786aaaf0f24ddc70cd602d93?s=96&d=mm&r=g","caption":"Monish Mohan"},"url":"https:\/\/blog-github-com-develop.go-vip.co\/jp\/author\/monishcm\/"}]}},"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/blog-github-com-develop.go-vip.co\/jp\/wp-content\/uploads\/sites\/2\/2022\/08\/npm-github.png?fit=1200%2C630","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/pat7HP-Vm","_links":{"self":[{"href":"https:\/\/blog-github-com-develop.go-vip.co\/jp\/wp-json\/wp\/v2\/posts\/3556","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog-github-com-develop.go-vip.co\/jp\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog-github-com-develop.go-vip.co\/jp\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog-github-com-develop.go-vip.co\/jp\/wp-json\/wp\/v2\/users\/2027"}],"replies":[{"embeddable":true,"href":"https:\/\/blog-github-com-develop.go-vip.co\/jp\/wp-json\/wp\/v2\/comments?post=3556"}],"version-history":[{"count":13,"href":"https:\/\/blog-github-com-develop.go-vip.co\/jp\/wp-json\/wp\/v2\/posts\/3556\/revisions"}],"predecessor-version":[{"id":3585,"href":"https:\/\/blog-github-com-develop.go-vip.co\/jp\/wp-json\/wp\/v2\/posts\/3556\/revisions\/3585"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog-github-com-develop.go-vip.co\/jp\/wp-json\/wp\/v2\/media\/3576"}],"wp:attachment":[{"href":"https:\/\/blog-github-com-develop.go-vip.co\/jp\/wp-json\/wp\/v2\/media?parent=3556"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog-github-com-develop.go-vip.co\/jp\/wp-json\/wp\/v2\/categories?post=3556"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog-github-com-develop.go-vip.co\/jp\/wp-json\/wp\/v2\/tags?post=3556"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/blog-github-com-develop.go-vip.co\/jp\/wp-json\/wp\/v2\/coauthors?post=3556"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}