@adobe/spacecat-shared-data-access
Shared modules of the Spacecat Services - Data Access
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions publisher is confirmed by SLSA/Sigstore attestation on the same release; consistent with Adobe CI/CD automation. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): 510 versions published; high-frequency release cadence makes dormancy flag unreliable for this package. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Decodes a pagination cursor into a JSON offset integer — no code execution or exfiltration risk. | ai | |
| phantom-deps | phantom-dep:@types/joi | AI (phantom-deps): Type-only package; loaded by convention, not direct import. Stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:aws-xray-sdk | AI (phantom-deps): Referenced in config files per analyzer note; stable false positive for this package. | ai |
Versions (showing 51 of 169)
| Version | Deps | Published |
|---|---|---|
| 4.14.0 | 9 / 7 | |
| 4.13.0 | 9 / 6 | |
| 4.12.0 | 9 / 6 | |
| 4.11.0 | 9 / 6 | |
| 4.10.1 | 9 / 6 | |
| 4.10.0 | 9 / 6 | |
| 4.9.0 | 9 / 6 | |
| 4.8.0 | 9 / 6 | |
| 4.7.0 | 9 / 6 | |
| 4.6.0 | 9 / 6 | |
| 4.5.0 | 9 / 6 | |
| 4.4.0 | 9 / 6 | |
| 4.3.1 | 9 / 6 | |
| 4.3.0 | 9 / 6 | |
| 4.2.0 | 9 / 6 | |
| 4.1.1 | 9 / 6 | |
| 4.1.0 | 9 / 6 | |
| 4.0.0 | 9 / 6 | |
| 3.81.0 | 9 / 6 | |
| 3.80.0 | 9 / 6 | |
| 3.79.1 | 9 / 6 | |
| 3.79.0 | 9 / 6 | |
| 3.78.0 | 9 / 6 | |
| 3.77.0 | 9 / 6 | |
| 3.76.0 | 9 / 6 | |
| 3.75.4 | 9 / 6 | |
| 3.75.3 | 9 / 6 | |
| 3.75.2 | 8 / 6 | |
| 3.75.1 | 8 / 6 | |
| 3.75.0 | 8 / 6 | |
| 3.74.3 | 8 / 6 | |
| 3.74.2 | 8 / 6 | |
| 3.74.1 | 8 / 6 | |
| 3.74.0 | 8 / 6 | |
| 3.73.3 | 8 / 6 | |
| 3.73.2 | 8 / 6 | |
| 3.73.1 | 8 / 5 | |
| 3.73.0 | 8 / 5 | |
| 3.72.1 | 8 / 5 | |
| 3.72.0 | 8 / 5 | |
| 3.71.2 | 8 / 5 | |
| 3.71.1 | 8 / 5 | |
| 3.71.0 | 8 / 5 | |
| 3.70.2 | 8 / 5 | |
| 3.70.1 | 8 / 5 | |
| 3.70.0 | 8 / 5 | |
| 3.69.0 | 8 / 5 | |
| 3.68.0 | 8 / 5 | |
| 3.67.0 | 8 / 5 | |
| 3.66.0 | 8 / 5 | |
| 3.65.0 | 8 / 5 |
v4.14.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.13.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.12.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.11.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.10.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.10.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.9.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.8.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.7.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.6.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.5.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.4.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.3.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.3.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.2.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.1.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.1.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.81.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.80.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.