← Home

@appium/logger

A Universal Logger For The Appium Ecosystem

11
Versions
ISC
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

jlippsnick.mokhnachkazucocoa

Keywords

androidautomationfirefoxosiosjavascriptseleniumtestingwebdriver

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Appium migrated to GitHub Actions for automated publishing; SLSA attestation confirms releases originate from the official appium/appium repo. Publisher change is a stable, legitimate transition for this package. ai
publish-pattern dormant-publish AI (publish-pattern): Irregular release cadence is normal for this scoped monorepo package; SLSA provenance attestation confirms the release is from the official CI pipeline, ruling out account takeover. ai

Versions (showing 11 of 11)

Version Deps Published
2.0.10 1 / 0
2.0.9 1 / 0
2.0.8 3 / 0
2.0.7 4 / 0
2.0.6 4 / 0
2.0.5 4 / 0
2.0.4 4 / 0
2.0.3 4 / 0
2.0.2 4 / 0
2.0.1 4 / 0
2.0.0 4 / 0

v2.0.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.