@apollo/federation-internals
Apollo Federation internal utilities
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Apollo Federation migrated publishing to GitHub Actions CI/CD with SLSA provenance attestation. The transition from individual account to GitHub Actions is a legitimate and more secure publishing pattern for this org. | ai | |
| phantom-deps | phantom-dep:@types/uuid | AI (phantom-deps): @types/uuid is intentionally listed as a runtime dep in this package (pre-existing pattern); not a security concern. | ai |
Versions (showing 17 of 17)
| Version | Deps | Published |
|---|---|---|
| 2.14.3 | 4 / 0 | |
| 2.14.2 | 4 / 0 | |
| 2.14.1 | 4 / 0 | |
| 2.14.0 | 4 / 0 | |
| 2.13.4 | 4 / 0 | |
| 2.13.3 | 4 / 0 | |
| 2.12.4 | 4 / 0 | |
| 2.12.3 | 4 / 0 | |
| 2.11.7 | 4 / 0 | |
| 2.11.6 | 4 / 0 | |
| 2.10.5 | 4 / 0 | |
| 2.13.0-preview.2 | 4 / 0 | |
| 2.13.0-preview.1 | 4 / 0 | |
| 2.13.0-preview.0 | 4 / 0 | |
| 2.12.0-preview.4 | 4 / 0 | |
| 2.11.5-preview.1 | 4 / 0 | |
| 2.11.5-preview.0 | 4 / 0 |
v2.14.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.13.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.12.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.11.7
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (dkuc) on unknown date, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.