@assistant-ui/react
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:zustand | AI (phantom-deps): Re-exported via Radix UI dependencies; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@radix-ui/react-use-callback-ref | AI (phantom-deps): Direct dependency used in component exports; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@radix-ui/react-compose-refs | AI (phantom-deps): Direct dependency used in component exports; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@radix-ui/react-primitive | AI (phantom-deps): Direct dependency used in component exports; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:react-textarea-autosize | AI (phantom-deps): Direct dependency used in component exports; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@radix-ui/react-slot | AI (phantom-deps): Direct dependency used in component exports; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@radix-ui/primitive | AI (phantom-deps): Direct dependency used in component exports; stable pattern for this package. | ai | |
| provenance | regressed-provenance | AI (provenance): Manual publish by known maintainer yonom; publishConfig provenance:false is intentional for this package. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): safe-content-frame is a first-party @assistant-ui-adjacent dep; benign additions expected across versions. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): JWT base64url decoding in auth code, not obfuscation. | ai | |
| provenance | slsa-provenance | AI (provenance): Package has SLSA provenance via Sigstore; strongest supply chain integrity signal, stable for this package going forward. | ai | |
| source-diff | large-new-source-files | AI (source-diff): UI component library for AI chat; adding new source files is expected growth. No large files (≥50KB) flagged, no script or dep changes — consistent with normal feature development. | ai | |
| dependencies | unvetted-dep:@radix-ui/react-dropdown-menu | AI (dependencies): @radix-ui/react-dropdown-menu is a well-known, widely-trusted Radix UI component; entirely appropriate for a React UI component library. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Dormancy followed by CI/CD-published release with SLSA provenance is consistent with legitimate resumption of development, not account takeover. | ai | |
| provenance | publisher-changed | AI (provenance): Publisher changed from yonom to GitHub Actions CI/CD, consistent with intentional migration to automated publishing with SLSA provenance attestation. Not a suspicious actor. | ai | |
| phantom-deps | phantom-dep:@standard-schema/spec | AI (phantom-deps): @standard-schema/spec is a legitimate schema spec package used at config/type level; not being directly imported in source is expected for this kind of dependency. | ai | |
| dependencies | unvetted-dep:@assistant-ui/store | AI (dependencies): First-party scoped package from the assistant-ui org; expected internal dependency. | ai | |
| dependencies | unvetted-dep:@assistant-ui/core | AI (dependencies): First-party scoped package from the assistant-ui org; expected internal dependency. | ai | |
| dependencies | unvetted-dep:@assistant-ui/tap | AI (dependencies): First-party scoped package from the assistant-ui org; expected internal dependency. | ai | |
| dependencies | unvetted-dep:assistant-stream | AI (dependencies): First-party dependency from the assistant-ui ecosystem, same publisher and GitHub org. | ai | |
| dependencies | unvetted-dep:radix-ui | AI (dependencies): radix-ui is a well-known React UI primitives library; expected dependency for this UI component package. | ai | |
| dependencies | unvetted-dep:assistant-cloud | AI (dependencies): First-party dependency from the assistant-ui ecosystem, same publisher and GitHub org. | ai | |
| phantom-deps | phantom-dep:nanoid | AI (phantom-deps): nanoid is a well-known ID generation library; phantom-dep finding is benign for a build/config reference. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): zod is a well-known validation library; phantom-dep finding is benign for a build/config reference. | ai |
Versions (showing 100 of 427)
| Version | Deps | Published |
|---|---|---|
| 0.7.73 | 23 / 12 | |
| 0.7.72 | 23 / 12 | |
| 0.7.71 | 23 / 12 | |
| 0.7.70 | 23 / 12 | |
| 0.7.69 | 23 / 12 | |
| 0.7.68 | 23 / 12 | |
| 0.7.67 | 23 / 12 | |
| 0.7.66 | 23 / 12 | |
| 0.7.65 | 23 / 12 | |
| 0.7.64 | 23 / 12 | |
| 0.7.63 | 23 / 12 | |
| 0.7.62 | 23 / 12 | |
| 0.7.61 | 23 / 12 | |
| 0.7.60 | 23 / 12 | |
| 0.7.59 | 23 / 12 | |
| 0.7.58 | 23 / 12 | |
| 0.7.57 | 23 / 12 | |
| 0.7.56 | 23 / 12 | |
| 0.7.55 | 23 / 12 | |
| 0.7.54 | 23 / 12 | |
| 0.7.53 | 23 / 12 | |
| 0.7.52 | 23 / 12 | |
| 0.7.51 | 23 / 12 | |
| 0.7.50 | 23 / 12 | |
| 0.7.49 | 23 / 12 | |
| 0.7.48 | 23 / 12 | |
| 0.7.47 | 23 / 12 | |
| 0.7.46 | 23 / 12 | |
| 0.7.45 | 23 / 12 | |
| 0.7.44 | 23 / 12 | |
| 0.7.43 | 23 / 12 | |
| 0.7.42 | 23 / 12 | |
| 0.7.41 | 23 / 12 | |
| 0.7.40 | 23 / 12 | |
| 0.7.39 | 23 / 12 | |
| 0.7.38 | 22 / 16 | |
| 0.7.37 | 22 / 16 | |
| 0.7.36 | 22 / 16 | |
| 0.7.35 | 22 / 16 | |
| 0.7.34 | 22 / 16 | |
| 0.7.33 | 22 / 16 | |
| 0.7.32 | 22 / 16 | |
| 0.7.31 | 22 / 16 | |
| 0.7.30 | 22 / 16 | |
| 0.7.29 | 22 / 16 | |
| 0.7.28 | 22 / 16 | |
| 0.7.27 | 22 / 16 | |
| 0.7.26 | 22 / 16 | |
| 0.7.25 | 22 / 16 | |
| 0.7.24 | 22 / 16 | |
| 0.7.23 | 22 / 16 | |
| 0.7.22 | 22 / 16 | |
| 0.7.21 | 22 / 16 | |
| 0.7.20 | 22 / 16 | |
| 0.7.19 | 22 / 16 | |
| 0.7.18 | 22 / 16 | |
| 0.7.17 | 22 / 16 | |
| 0.7.16 | 22 / 16 | |
| 0.7.15 | 22 / 16 | |
| 0.7.14 | 22 / 16 | |
| 0.7.12 | 22 / 16 | |
| 0.7.11 | 22 / 16 | |
| 0.7.10 | 22 / 16 | |
| 0.7.9 | 22 / 16 | |
| 0.7.8 | 22 / 16 | |
| 0.7.7 | 22 / 16 | |
| 0.7.6 | 22 / 16 | |
| 0.7.5 | 22 / 16 | |
| 0.7.4 | 22 / 16 | |
| 0.7.3 | 22 / 16 | |
| 0.7.2 | 22 / 16 | |
| 0.7.1 | 22 / 16 | |
| 0.7.0 | 22 / 16 | |
| 0.5.100 | 22 / 16 | |
| 0.5.99 | 22 / 16 | |
| 0.5.98 | 22 / 16 | |
| 0.5.97 | 22 / 14 | |
| 0.5.96 | 22 / 14 | |
| 0.5.95 | 22 / 14 | |
| 0.5.94 | 22 / 14 | |
| 0.5.93 | 22 / 14 | |
| 0.5.92 | 22 / 14 | |
| 0.5.91 | 22 / 14 | |
| 0.5.90 | 22 / 13 | |
| 0.5.89 | 22 / 13 | |
| 0.5.88 | 22 / 13 | |
| 0.5.87 | 22 / 13 | |
| 0.5.86 | 22 / 13 | |
| 0.5.85 | 22 / 13 | |
| 0.5.84 | 22 / 13 | |
| 0.5.83 | 22 / 13 | |
| 0.5.82 | 22 / 13 | |
| 0.5.81 | 22 / 13 | |
| 0.5.80 | 22 / 13 | |
| 0.5.79 | 22 / 13 | |
| 0.5.78 | 22 / 13 | |
| 0.5.77 | 22 / 13 | |
| 0.5.76 | 21 / 13 | |
| 0.5.75 | 21 / 13 | |
| 0.5.74 | 21 / 13 |
v0.7.73
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.72
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.71
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.70
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.69
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.68
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.67
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.66
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.65
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.64
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.63
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.62
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.61
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.60
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.59
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.58
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.57
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.56
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.55
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.54
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.53
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.52
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.51
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.50
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.49
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.48
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.47
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.46
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.45
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.44
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.43
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.42
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.41
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.40
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.39
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.38
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.37
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.36
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.35
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.34
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.33
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.32
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.31
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.30
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.29
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.28
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.27
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.26
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.25
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.24
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.23
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.22
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.21
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.20
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.19
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.18
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.17
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.16
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.15
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.14
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.100
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.99
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.98
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.97
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.96
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.95
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.94
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.93
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.92
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.91
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.90
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.89
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.88
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.87
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.86
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.85
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.84
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.83
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.82
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.81
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.80
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.79
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.78
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.77
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.76
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.75
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.74
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.