Evidence-backed facts
- npm, Inc. documents package manifests, versions, distribution metadata, tarballs, tags, access rules, and registry configuration. informative
- Public reads are separate from token-protected publish, unpublish, owner, or private-package operations; credentials must remain secret and access does not grant package ownership. informative
- Clients must bind registry base URL, scoped package encoding, version or tag, manifest, tarball integrity, authentication, cache, and client configuration. informative
- Registry metadata and package presence can change or be publisher-controlled and do not prove author identity, code safety, maintenance, licensing, or compatibility. informative