← Home

@adobe/spacecat-shared-utils

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

marbectripodgarthdblazdadobe-adminpatrickfultontrieloffkrisnyedcpfsdknatebaldwindevongovettaspro83symanovidpfisterstefan-guggisbergrofekptdobeadobehallsfullcolorcoderdjaeggidylandepassmhaackamol-anandstopp-adobenamaroradotenduh_schmidtasthabh23zdahbituicufmeschbe

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Adobe org migrated publishing to GitHub Actions CI/CD; SLSA provenance attestation confirms supply chain integrity. ai
dependencies unvetted-dep:@adobe/spacecat-shared-ims-client AI (dependencies): First-party Adobe/spacecat package from the same org and publisher lineage. ai
dependencies unvetted-dep:aws-xray-sdk AI (dependencies): aws-xray-sdk is an official AWS observability SDK; no malware indicators, stable dependency for this package. ai
dependencies unvetted-dep:@json2csv/plainjs AI (dependencies): @json2csv/plainjs is a well-known CSV conversion library; no malware indicators, stable dependency for this package. ai

Versions (showing 51 of 233)

View all versions
Version Deps Published
1.125.0 14 / 10
1.124.1 14 / 10
1.124.0 14 / 10
1.123.1 14 / 10
1.123.0 14 / 10
1.122.1 14 / 10
1.122.0 14 / 10
1.121.0 14 / 10
1.120.1 14 / 10
1.120.0 14 / 10
1.119.3 14 / 10
1.119.2 14 / 10
1.119.1 14 / 10
1.119.0 14 / 10
1.118.0 14 / 10
1.117.0 14 / 10
1.116.6 14 / 10
1.116.5 14 / 10
1.116.4 14 / 10
1.116.3 14 / 10
1.116.2 14 / 10
1.116.1 14 / 10
1.116.0 14 / 10
1.115.4 14 / 10
1.115.3 13 / 10
1.115.2 13 / 10
1.115.1 13 / 10
1.115.0 13 / 10
1.114.0 13 / 10
1.113.0 13 / 10
1.112.5 13 / 10
1.112.4 13 / 10
1.112.3 13 / 10
1.112.2 13 / 10
1.112.1 13 / 10
1.112.0 13 / 10
1.111.0 13 / 9
1.110.0 13 / 9
1.109.0 13 / 9
1.108.0 13 / 9
1.107.0 13 / 9
1.106.1 13 / 9
1.106.0 13 / 9
1.105.1 13 / 9
1.105.0 13 / 9
1.104.0 13 / 9
1.103.0 13 / 9
1.102.1 13 / 9
1.102.0 13 / 9
1.101.0 13 / 9
1.100.1 13 / 9

v1.125.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.124.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.124.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.123.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.115.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.115.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.115.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.115.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.113.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.112.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.112.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.112.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.112.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.108.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.106.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.106.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.105.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.101.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.100.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.