← Home

@adobe/helix-deploy

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

marbectripodgarthdblazdadobe-adminpatrickfultontrieloffkrisnyedcpfsdknatebaldwindevongovettaspro83symanovidpfisterstefan-guggisbergrofekptdobeadobehallsfullcolorcoderdjaeggidylandepassmhaackamol-anandstopp-adobenamaroradotenduh_schmidtasthabh23zdahbituicufmeschbe

Keywords

helixserverless

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:env-bulk-read AI (semgrep): CLI tool reads process.env to substitute vars into deployment configs — documented, expected behavior for this deploy tool. ai

Versions (showing 51 of 53)

View all versions
Version Deps Published
14.3.0 19 / 17
14.2.0 19 / 17
14.1.1 19 / 17
14.1.0 18 / 17
14.0.12 18 / 17
14.0.11 18 / 17
14.0.10 18 / 17
14.0.9 18 / 17
14.0.8 18 / 17
14.0.7 18 / 17
14.0.6 18 / 17
14.0.5 18 / 17
14.0.4 18 / 17
14.0.3 18 / 17
14.0.2 18 / 17
14.0.1 18 / 17
14.0.0 18 / 17
13.5.8 21 / 17
13.5.7 21 / 17
13.5.6 21 / 17
13.5.5 21 / 17
13.5.4 21 / 17
13.5.3 21 / 17
13.5.2 21 / 17
13.5.1 21 / 17
13.5.0 21 / 17
13.4.1 21 / 17
13.4.0 21 / 17
13.3.3 21 / 17
13.3.2 21 / 17
13.3.1 21 / 17
13.3.0 21 / 17
13.2.15 21 / 17
13.2.14 21 / 17
13.2.13 21 / 17
13.2.12 21 / 17
13.2.11 21 / 17
13.2.10 21 / 17
13.2.9 21 / 17
13.2.8 21 / 17
13.2.7 21 / 17
13.2.6 21 / 17
13.2.5 21 / 17
13.2.4 21 / 17
13.2.3 21 / 17
13.2.2 21 / 17
13.2.1 21 / 17
13.2.0 21 / 17
13.1.25 21 / 16
13.1.24 21 / 16
13.1.23 21 / 16

v14.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v14.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v14.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v14.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v14.0.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v14.0.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v14.0.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.