← Home

@axium/core

87
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

james-pre

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
install-scripts install-script:postinstall AI (install-scripts): Runs subpatch per package's own subpatch config; documented patch-apply step, not arbitrary code. ai
dependencies unvetted-dep:subpatch AI (dependencies): subpatch is the tool invoked by postinstall and declared in package.json config; consistent with stated use. ai
typosquat typosquat.levenshtein:cors AI (typosquat): Scoped package @axium/core is the core module of the axium project, not a typosquat of cors. Name similarity is coincidental. ai
phantom-deps phantom-dep:@types/semver AI (phantom-deps): @types/semver is a type declaration package; not directly imported at runtime but used for TypeScript type resolution alongside semver. ai

Versions (showing 87 of 87)

Version Deps Published
0.37.1 5 / 0
0.37.0 4 / 0
0.36.2 4 / 0
0.36.1 4 / 0
0.36.0 4 / 0
0.35.0 4 / 0
0.34.0 4 / 0
0.33.0 4 / 0
0.32.1 4 / 0
0.32.0 4 / 0
0.31.1 4 / 0
0.31.0 4 / 0
0.30.1 4 / 0
0.30.0 4 / 0
0.29.0 4 / 0
0.28.3 4 / 0
0.28.2 4 / 0
0.28.1 4 / 0
0.28.0 4 / 0
0.27.6 4 / 0
0.27.5 4 / 0
0.27.4 4 / 0
0.27.3 4 / 0
0.27.2 4 / 0
0.27.1 4 / 0
0.27.0 4 / 0
0.26.2 4 / 0
0.26.1 4 / 0
0.26.0 4 / 0
0.25.0 4 / 0
0.24.0 4 / 0
0.23.0 3 / 0
0.22.2 3 / 0
0.22.1 3 / 0
0.22.0 3 / 0
0.21.1 3 / 0
0.21.0 3 / 0
0.20.3 3 / 0
0.20.2 3 / 0
0.20.1 3 / 0
0.20.0 3 / 0
0.19.7 3 / 0
0.19.6 3 / 0
0.19.5 3 / 0
0.19.4 3 / 0
0.19.3 3 / 0
0.19.2 4 / 0
0.19.1 4 / 0
0.19.0 4 / 0
0.18.2 4 / 0
0.18.1 4 / 0
0.18.0 4 / 0
0.17.1 4 / 0
0.17.0 4 / 0
0.16.0 4 / 0
0.15.2 4 / 0
0.15.1 4 / 0
0.15.0 4 / 0
0.14.0 4 / 0
0.13.0 4 / 0
0.12.1 2 / 0
0.12.0 2 / 0
0.11.0 2 / 0
0.10.0 2 / 0
0.9.0 2 / 0
0.8.0 2 / 0
0.7.0 2 / 0
0.6.0 2 / 0
0.5.5 2 / 0
0.5.4 2 / 0
0.5.3 2 / 0
0.5.2 2 / 0
0.5.1 2 / 0
0.5.0 2 / 0
0.4.5 2 / 0
0.4.4 2 / 0
0.4.3 2 / 0
0.4.2 1 / 0
0.4.1 1 / 0
0.4.0 1 / 0
0.3.0 1 / 0
0.2.0 2 / 0
0.1.1 1 / 0
0.1.0 1 / 0
0.0.3 1 / 0
0.0.2 1 / 0
0.0.1 1 / 0

v0.37.1

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: subpatch

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.37.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.36.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.36.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.36.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.35.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.