← Home

@apify/log

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

mtrunkatjancurnpetrpatekmnmkngjaroslavhejlekdrobnikjmetalwarrior665fnesvedab4nanjanbucharapify-service-account

Keywords

apify

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
typosquat typosquat.levenshtein:koa AI (typosquat): Scoped @apify package; not a typosquat of koa. ai
typosquat typosquat.levenshtein:got AI (typosquat): Scoped @apify package; not a typosquat of got. ai
typosquat typosquat.levenshtein:pg AI (typosquat): Scoped @apify package; not a typosquat of pg. ai
typosquat typosquat.levenshtein:joi AI (typosquat): Scoped @apify package; not a typosquat of joi. ai
typosquat typosquat.levenshtein:zod AI (typosquat): Scoped @apify package; not a typosquat of zod. ai
typosquat typosquat.levenshtein:glob AI (typosquat): Scoped @apify package; not a typosquat of glob. ai

Versions (showing 51 of 85)

View all versions
Version Deps Published
2.5.44 2 / 0
2.5.43 2 / 0
2.5.42 2 / 0
2.5.41 2 / 0
2.5.40 2 / 0
2.5.39 2 / 0
2.5.38 2 / 0
2.5.37 2 / 0
2.5.36 2 / 0
2.5.35 2 / 0
2.5.34 2 / 0
2.5.33 2 / 0
2.5.32 2 / 0
2.5.31 2 / 0
2.5.30 2 / 0
2.5.29 2 / 0
2.5.28 2 / 0
2.5.27 2 / 0
2.5.26 2 / 0
2.5.25 2 / 0
2.5.24 2 / 0
2.5.23 2 / 0
2.5.22 2 / 0
2.5.21 2 / 0
2.5.20 2 / 0
2.5.19 2 / 0
2.5.18 2 / 0
2.5.17 2 / 0
2.5.16 2 / 0
2.5.15 2 / 0
2.5.14 2 / 0
2.5.13 2 / 0
2.5.12 2 / 0
2.5.11 2 / 0
2.5.10 2 / 0
2.5.9 2 / 0
2.5.8 2 / 0
2.5.7 2 / 0
2.5.6 2 / 0
2.5.5 2 / 0
2.5.4 2 / 0
2.5.3 2 / 0
2.5.2 2 / 0
2.5.1 2 / 0
2.5.0 2 / 0
2.4.9 2 / 0
2.4.8 2 / 0
2.4.7 2 / 0
2.4.6 2 / 0
2.4.5 2 / 0
2.4.4 2 / 0

v2.5.44

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.5.43

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.5.42

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.5.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.5.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.