← Home

@atproto/oauth-client-node

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

dholmspfrazeedevinivyestrattonbaileymatthieu-bluesky

Keywords

atprotooauthclientnode

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition from devinivy to GitHub Actions CI/CD is legitimate; SLSA attestation confirms official repo provenance. ai
publish-pattern dormant-publish AI (publish-pattern): Dormancy followed by GitHub Actions publishing reflects CI/CD migration, not account takeover; SLSA attestation confirms integrity. ai
phantom-deps phantom-dep:@atproto/did AI (phantom-deps): Same-org @atproto scope; phantom-dep heuristic fires on indirect usage patterns common in monorepo packages. ai
phantom-deps phantom-dep:@atproto-labs/did-resolver AI (phantom-deps): Same-org @atproto-labs scope; referenced in config files as noted, stable false positive for this package. ai

Versions (showing 51 of 65)

View all versions
Version Deps Published
0.4.9 9 / 0
0.4.8 9 / 0
0.4.7 9 / 0
0.4.6 9 / 0
0.4.5 9 / 0
0.4.4 9 / 0
0.4.3 9 / 0
0.4.2 9 / 0
0.4.1 9 / 1
0.4.0 9 / 1
0.3.17 9 / 1
0.3.16 9 / 1
0.3.15 9 / 1
0.3.14 9 / 1
0.3.13 9 / 1
0.3.12 9 / 1
0.3.11 9 / 1
0.3.10 9 / 1
0.3.9 9 / 1
0.3.8 9 / 1
0.3.7 9 / 1
0.3.6 9 / 1
0.3.5 9 / 1
0.3.4 9 / 1
0.3.3 9 / 1
0.3.2 9 / 1
0.3.1 9 / 1
0.3.0 9 / 1
0.2.24 9 / 1
0.2.23 9 / 1
0.2.22 9 / 1
0.2.21 9 / 1
0.2.20 9 / 1
0.2.19 9 / 1
0.2.18 9 / 1
0.2.17 9 / 1
0.2.16 9 / 1
0.2.15 9 / 1
0.2.14 9 / 1
0.2.13 9 / 1
0.2.12 9 / 1
0.2.11 9 / 1
0.2.10 9 / 1
0.2.9 9 / 1
0.2.8 9 / 1
0.2.7 9 / 1
0.2.6 9 / 1
0.2.5 9 / 1
0.2.4 9 / 1
0.2.3 9 / 1
0.2.2 9 / 1

v0.4.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.