← Home

@aegisjsproject/router

A simple but powerful router module

4
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

shgysk8zer0

Keywords

routerclient-sideesmnavigationsingle-page-appspaurl-managementurl-patternevent-handlingdynamic-importsa11ymodule-handlersweb-componentspreloadingvanilla

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern dormant-publish AI (publish-pattern): SLSA provenance attestation via GitHub Actions CI provides strong supply chain integrity; dormancy alone is not disqualifying here. ai
dependencies unvetted-dep:@aegisjsproject/state AI (dependencies): Same-org dependency (@aegisjsproject) consistent with the package's ecosystem; not a third-party risk. ai
provenance slsa-provenance AI (provenance): Package consistently published via CI with Sigstore attestation; stable supply chain signal for this package. ai

Versions (showing 4 of 4)

Version Deps Published
1.2.0 1 / 12
1.1.15 1 / 12
1.1.14 1 / 12
1.1.12 1 / 12

v1.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.15

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.14

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.