based on my reading of https://www.zachleat.com/web/npm-security/ pointing to https://docs.npmjs.com/trusted-publishers (this would usefully be done for browser-specs as well)