@across-protocol/constants
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions CI publisher with SLSA attestation; consistent with org-level automation adoption. | ai |
Versions (showing 51 of 121)
| Version | Deps | Published |
|---|---|---|
| 3.1.123 | 0 / 12 | |
| 3.1.122 | 0 / 12 | |
| 3.1.120 | 0 / 12 | |
| 3.1.119 | 0 / 12 | |
| 3.1.118 | 0 / 12 | |
| 3.1.117 | 0 / 12 | |
| 3.1.116 | 0 / 12 | |
| 3.1.115 | 0 / 12 | |
| 3.1.114 | 0 / 12 | |
| 3.1.113 | 0 / 12 | |
| 3.1.112 | 0 / 12 | |
| 3.1.111 | 0 / 12 | |
| 3.1.110 | 0 / 12 | |
| 3.1.109 | 0 / 12 | |
| 3.1.108 | 0 / 12 | |
| 3.1.107 | 0 / 12 | |
| 3.1.106 | 0 / 12 | |
| 3.1.105 | 0 / 12 | |
| 3.1.104 | 0 / 12 | |
| 3.1.103 | 0 / 12 | |
| 3.1.102 | 0 / 12 | |
| 3.1.101 | 0 / 12 | |
| 3.1.100 | 0 / 12 | |
| 3.1.99 | 0 / 12 | |
| 3.1.98 | 0 / 12 | |
| 3.1.97 | 0 / 12 | |
| 3.1.96 | 0 / 12 | |
| 3.1.95 | 0 / 12 | |
| 3.1.94 | 0 / 12 | |
| 3.1.93 | 0 / 12 | |
| 3.1.91 | 0 / 12 | |
| 3.1.90 | 0 / 12 | |
| 3.1.89 | 0 / 12 | |
| 3.1.88 | 0 / 12 | |
| 3.1.87 | 0 / 12 | |
| 3.1.86 | 0 / 12 | |
| 3.1.85 | 0 / 12 | |
| 3.1.84 | 0 / 12 | |
| 3.1.83 | 0 / 12 | |
| 3.1.82 | 0 / 12 | |
| 3.1.81 | 0 / 12 | |
| 3.1.80 | 0 / 12 | |
| 3.1.79 | 0 / 12 | |
| 3.1.78 | 0 / 12 | |
| 3.1.77 | 0 / 12 | |
| 3.1.76 | 0 / 12 | |
| 3.1.75 | 0 / 12 | |
| 3.1.74 | 0 / 12 | |
| 3.1.73 | 0 / 12 | |
| 3.1.72 | 0 / 12 | |
| 3.1.71 | 0 / 12 |
v3.1.123
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.1.122
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.1.120
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.1.119
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.1.118
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.1.117
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.