drop npm sigstore provenance bundle · parse publisher + build config + tarball digest · runs locally
drop npm sigstore provenance bundle · local only
heuristic screener · vendor schema varies · not definitive proof