@adobe/spacecat-shared-data-access
Shared modules of the Spacecat Services - Data Access
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions publisher is confirmed by SLSA/Sigstore attestation on the same release; consistent with Adobe CI/CD automation. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): 510 versions published; high-frequency release cadence makes dormancy flag unreliable for this package. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Decodes a pagination cursor into a JSON offset integer — no code execution or exfiltration risk. | ai | |
| phantom-deps | phantom-dep:@types/joi | AI (phantom-deps): Type-only package; loaded by convention, not direct import. Stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:aws-xray-sdk | AI (phantom-deps): Referenced in config files per analyzer note; stable false positive for this package. | ai |
Versions (showing 100 of 169)
| Version | Deps | Published |
|---|---|---|
| 4.14.0 | 9 / 7 | |
| 4.13.0 | 9 / 6 | |
| 4.12.0 | 9 / 6 | |
| 4.11.0 | 9 / 6 | |
| 4.10.1 | 9 / 6 | |
| 4.10.0 | 9 / 6 | |
| 4.9.0 | 9 / 6 | |
| 4.8.0 | 9 / 6 | |
| 4.7.0 | 9 / 6 | |
| 4.6.0 | 9 / 6 | |
| 4.5.0 | 9 / 6 | |
| 4.4.0 | 9 / 6 | |
| 4.3.1 | 9 / 6 | |
| 4.3.0 | 9 / 6 | |
| 4.2.0 | 9 / 6 | |
| 4.1.1 | 9 / 6 | |
| 4.1.0 | 9 / 6 | |
| 4.0.0 | 9 / 6 | |
| 3.81.0 | 9 / 6 | |
| 3.80.0 | 9 / 6 | |
| 3.79.1 | 9 / 6 | |
| 3.79.0 | 9 / 6 | |
| 3.78.0 | 9 / 6 | |
| 3.77.0 | 9 / 6 | |
| 3.76.0 | 9 / 6 | |
| 3.75.4 | 9 / 6 | |
| 3.75.3 | 9 / 6 | |
| 3.75.2 | 8 / 6 | |
| 3.75.1 | 8 / 6 | |
| 3.75.0 | 8 / 6 | |
| 3.74.3 | 8 / 6 | |
| 3.74.2 | 8 / 6 | |
| 3.74.1 | 8 / 6 | |
| 3.74.0 | 8 / 6 | |
| 3.73.3 | 8 / 6 | |
| 3.73.2 | 8 / 6 | |
| 3.73.1 | 8 / 5 | |
| 3.73.0 | 8 / 5 | |
| 3.72.1 | 8 / 5 | |
| 3.72.0 | 8 / 5 | |
| 3.71.2 | 8 / 5 | |
| 3.71.1 | 8 / 5 | |
| 3.71.0 | 8 / 5 | |
| 3.70.2 | 8 / 5 | |
| 3.70.1 | 8 / 5 | |
| 3.70.0 | 8 / 5 | |
| 3.69.0 | 8 / 5 | |
| 3.68.0 | 8 / 5 | |
| 3.67.0 | 8 / 5 | |
| 3.66.0 | 8 / 5 | |
| 3.65.0 | 8 / 5 | |
| 3.64.0 | 8 / 5 | |
| 3.63.0 | 8 / 5 | |
| 3.62.0 | 8 / 5 | |
| 3.61.0 | 8 / 5 | |
| 3.60.0 | 8 / 5 | |
| 3.59.0 | 8 / 5 | |
| 3.58.0 | 8 / 5 | |
| 3.57.0 | 8 / 5 | |
| 3.56.1 | 8 / 5 | |
| 3.56.0 | 8 / 5 | |
| 3.55.1 | 8 / 5 | |
| 3.55.0 | 8 / 5 | |
| 3.54.0 | 8 / 5 | |
| 3.53.0 | 8 / 5 | |
| 3.52.0 | 8 / 5 | |
| 3.51.0 | 8 / 5 | |
| 3.50.1 | 8 / 5 | |
| 3.50.0 | 8 / 5 | |
| 3.49.0 | 8 / 5 | |
| 3.48.0 | 8 / 5 | |
| 3.47.0 | 8 / 5 | |
| 3.46.0 | 8 / 5 | |
| 3.45.2 | 8 / 5 | |
| 3.45.1 | 8 / 5 | |
| 3.45.0 | 8 / 5 | |
| 3.44.0 | 8 / 5 | |
| 3.43.0 | 8 / 5 | |
| 3.42.0 | 8 / 5 | |
| 3.41.0 | 8 / 5 | |
| 3.40.0 | 8 / 5 | |
| 3.39.0 | 8 / 5 | |
| 3.38.0 | 8 / 5 | |
| 3.37.0 | 8 / 5 | |
| 3.36.1 | 8 / 5 | |
| 3.36.0 | 8 / 5 | |
| 3.35.0 | 8 / 5 | |
| 3.34.0 | 8 / 5 | |
| 3.33.1 | 8 / 5 | |
| 3.33.0 | 8 / 5 | |
| 3.32.1 | 8 / 5 | |
| 3.32.0 | 8 / 5 | |
| 3.31.1 | 8 / 5 | |
| 3.31.0 | 8 / 5 | |
| 3.30.0 | 8 / 5 | |
| 3.29.0 | 8 / 5 | |
| 3.28.0 | 8 / 5 | |
| 3.27.0 | 8 / 5 | |
| 3.26.0 | 8 / 5 | |
| 3.25.0 | 8 / 5 |
v4.14.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.13.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.12.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.11.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.10.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.10.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.9.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.8.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.7.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.6.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.5.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.4.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.3.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.3.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.2.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.1.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.1.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.81.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.80.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.