One issue here is that NIST are trying to push SBOMs [2] but NPM is not providing them as part of the provenance I think.
Another thing is a push to use new types of signature envelopes like DSSE [3] instead of something like COSE [4]
[1] https://datatracker.ietf.org/group/scitt/about/
[2] https://www.nist.gov/itl/executive-order-14028-improving-nat...
[3] https://github.com/secure-systems-lab/dsse