← Home

@ashdev/codex-plugin-metadata-openlibrary

Open Library metadata plugin for Codex - fetches book metadata by ISBN or title search

100
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

4shdev

Keywords

codexpluginopenlibrarymetadatabooksisbn

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
npm-metadata url-dep:@ashdev/codex-plugin-sdk AI (npm-metadata): Local file: path is a monorepo workspace reference; SDK is bundled at build time, not fetched at runtime. ai
provenance publisher-changed AI (provenance): Transition from human publisher to GitHub Actions CI/CD is intentional; SLSA attestation confirms automated publishing pipeline. ai
phantom-deps phantom-dep:@ashdev/codex-plugin-sdk AI (phantom-deps): Same org scope; bundled via esbuild so import may not appear as a direct import in static analysis. ai

Versions (showing 100 of 109)

Version Deps Published
1.42.2 1 / 5
1.42.1 1 / 5
1.42.0 1 / 5
1.41.1 1 / 5
1.41.0 1 / 5
1.40.8 1 / 5
1.40.6 1 / 5
1.40.5 1 / 5
1.40.4 1 / 5
1.40.3 1 / 5
1.40.2 1 / 5
1.40.1 1 / 5
1.40.0 1 / 5
1.39.15 1 / 5
1.39.14 1 / 5
1.39.13 1 / 5
1.39.12 1 / 5
1.39.11 1 / 5
1.39.10 1 / 5
1.39.9 1 / 5
1.39.8 1 / 5
1.39.7 1 / 5
1.39.6 1 / 5
1.39.5 1 / 5
1.39.3 1 / 5
1.39.2 1 / 5
1.39.1 1 / 5
1.39.0 1 / 5
1.38.4 1 / 5
1.38.3 1 / 5
1.38.2 1 / 5
1.38.1 1 / 5
1.38.0 1 / 5
1.37.1 1 / 5
1.37.0 1 / 5
1.36.1 1 / 5
1.36.0 1 / 5
1.35.0 1 / 5
1.34.1 1 / 5
1.34.0 1 / 5
1.33.3 1 / 5
1.33.2 1 / 5
1.33.1 1 / 5
1.33.0 1 / 5
1.32.1 1 / 5
1.32.0 1 / 5
1.31.2 1 / 5
1.31.1 1 / 5
1.31.0 1 / 5
1.30.1 1 / 5
1.30.0 1 / 5
1.29.0 1 / 5
1.28.3 1 / 5
1.28.2 1 / 5
1.28.1 1 / 5
1.28.0 1 / 5
1.27.1 1 / 5
1.27.0 1 / 5
1.26.1 1 / 5
1.26.0 1 / 5
1.25.0 1 / 5
1.24.1 1 / 5
1.23.0 1 / 5
1.22.0 1 / 5
1.21.5 1 / 5
1.21.4 1 / 5
1.21.3 1 / 5
1.21.2 1 / 5
1.21.1 1 / 5
1.21.0 1 / 5
1.20.0 1 / 5
1.19.3 1 / 5
1.19.2 1 / 5
1.19.1 1 / 5
1.19.0 1 / 5
1.18.1 1 / 5
1.18.0 1 / 5
1.17.0 1 / 5
1.16.1 1 / 5
1.16.0 1 / 5
1.15.1 1 / 5
1.15.0 1 / 5
1.14.3 1 / 5
1.14.2 1 / 5
1.14.1 1 / 5
1.14.0 1 / 5
1.13.0 1 / 5
1.12.0 1 / 5
1.11.2 1 / 5
1.11.1 1 / 5
1.11.0 1 / 5
1.10.9 1 / 5
1.10.8 1 / 5
1.10.6 1 / 5
1.10.5 1 / 5
1.10.4 1 / 5
1.10.3 1 / 5
1.10.2 1 / 5
1.10.1 1 / 5
1.10.0 1 / 5
Showing 100 of 109 Next page →

v1.42.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.42.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.42.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.41.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.41.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.40.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.40.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.40.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.40.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.40.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.40.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.40.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.40.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.39.15

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.39.14

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.39.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.39.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.39.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.39.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.