@actions/artifact
9
Versions
—
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
bryanmacfarlanethboopericsciplebdehamer
Keywords
githubactionsartifact
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | dormant-publish | AI (publish-pattern): SLSA provenance attestation confirms CI/CD publish from official GitHub Actions org; dormancy explained by major rewrite. | ai | |
| phantom-deps | phantom-dep:tmp | AI (phantom-deps): tmp is a declared runtime dep used indirectly via tmp-promise; phantom-dep heuristic is a false positive here. | ai | |
| dependencies | unvetted-dep:@protobuf-ts/plugin | AI (dependencies): Build-time protobuf codegen tool; phantom-dep analysis confirms it is not directly imported at runtime. Stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@azure/core-http | AI (phantom-deps): Framework-scoped Azure SDK package loaded by convention; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@octokit/request-error | AI (phantom-deps): Transitive octokit dep declared for version pinning; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@protobuf-ts/plugin | AI (phantom-deps): Build-time protobuf generator; declared as dep but used only in build config, not directly imported at runtime. | ai | |
| phantom-deps | phantom-dep:@octokit/request | AI (phantom-deps): Transitive octokit dep declared for version pinning; stable false positive for this package. | ai |