@alwaysmeticulous/sdk-bundles-api
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): SLSA provenance attestation present; gitHead absence is superseded by stronger Sigstore/SLSA supply chain integrity signal. | ai | |
| provenance | publisher-changed | AI (provenance): Meticulous migrated to GitHub Actions CI publishing with SLSA attestation; this pattern is stable for this package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Internal SDK types package; sparse README and no keywords are expected for this kind of package. | ai |
Versions (showing 51 of 166)
| Version | Deps | Published |
|---|---|---|
| 2.312.0 | 1 / 0 | |
| 2.310.0 | 1 / 0 | |
| 2.307.0 | 1 / 0 | |
| 2.306.0 | 1 / 0 | |
| 2.305.0 | 1 / 0 | |
| 2.303.1 | 1 / 0 | |
| 2.297.0 | 1 / 0 | |
| 2.295.0 | 1 / 0 | |
| 2.294.0 | 1 / 0 | |
| 2.293.0 | 1 / 0 | |
| 2.292.1 | 1 / 0 | |
| 2.292.0 | 1 / 0 | |
| 2.291.2 | 1 / 0 | |
| 2.290.2 | 1 / 0 | |
| 2.290.0 | 1 / 0 | |
| 2.289.1 | 1 / 0 | |
| 2.288.2 | 1 / 0 | |
| 2.288.0 | 1 / 0 | |
| 2.287.0 | 1 / 0 | |
| 2.286.0 | 1 / 0 | |
| 2.285.2 | 1 / 0 | |
| 2.285.1 | 1 / 0 | |
| 2.285.0 | 1 / 0 | |
| 2.283.1 | 1 / 0 | |
| 2.280.0 | 1 / 0 | |
| 2.277.0 | 1 / 0 | |
| 2.276.2 | 1 / 0 | |
| 2.275.0 | 1 / 0 | |
| 2.274.2 | 1 / 0 | |
| 2.273.0 | 1 / 0 | |
| 2.271.0 | 1 / 0 | |
| 2.267.0 | 1 / 0 | |
| 2.266.2 | 1 / 0 | |
| 2.264.0 | 1 / 0 | |
| 2.262.1 | 1 / 0 | |
| 2.262.0 | 1 / 0 | |
| 2.260.2 | 1 / 0 | |
| 2.259.0 | 1 / 0 | |
| 2.257.1 | 1 / 0 | |
| 2.257.0 | 1 / 0 | |
| 2.256.0 | 1 / 0 | |
| 2.255.0 | 1 / 0 | |
| 2.254.1 | 1 / 0 | |
| 2.253.0 | 1 / 0 | |
| 2.251.1 | 1 / 0 | |
| 2.251.0 | 1 / 0 | |
| 2.250.7 | 1 / 0 | |
| 2.250.6 | 1 / 0 | |
| 2.250.5 | 1 / 0 | |
| 2.250.4 | 1 / 0 | |
| 2.250.3 | 1 / 0 |
v2.312.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.310.0
1 findingThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.
v2.307.0
1 findingThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.
v2.306.0
1 findingThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. The axios attack (March 2026) exhibited exactly this pattern.
v2.305.0
1 findingThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. The axios attack (March 2026) exhibited exactly this pattern.
v2.303.1
1 findingThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. The axios attack (March 2026) exhibited exactly this pattern.