← Home

@balena/open-balena-api

Internet of things, Made Simple

15
Versions
AGPL-3.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

balena.iopage

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@types/lodash AI (phantom-deps): TypeScript type package; stable false positive. ai
phantom-deps phantom-dep:@types/morgan AI (phantom-deps): TypeScript type package; stable false positive. ai
phantom-deps phantom-dep:@types/express AI (phantom-deps): TypeScript type package; stable false positive. ai
phantom-deps phantom-dep:@types/redlock AI (phantom-deps): TypeScript type package; stable false positive. ai
phantom-deps phantom-dep:@types/request AI (phantom-deps): TypeScript type package; stable false positive. ai
phantom-deps phantom-dep:@types/node AI (phantom-deps): Framework-scoped type package; stable false positive. ai
phantom-deps phantom-dep:@swc-node/register AI (phantom-deps): Test runner import in mocha config; stable false positive. ai
phantom-deps phantom-dep:@balena/es-version AI (phantom-deps): Same-org package used by convention; stable false positive. ai
phantom-deps phantom-dep:@opentelemetry/core AI (phantom-deps): OTel config-referenced package; stable false positive. ai
phantom-deps phantom-dep:@opentelemetry/sdk-node AI (phantom-deps): OTel config-referenced package; stable false positive. ai
phantom-deps phantom-dep:@swc/core AI (phantom-deps): Build tooling referenced in config files; stable pattern for this package. ai
phantom-deps phantom-dep:@opentelemetry/context-async-hooks AI (phantom-deps): OTel config-referenced package; stable false positive. ai
phantom-deps phantom-dep:@opentelemetry/instrumentation-http AI (phantom-deps): OTel config-referenced package; stable false positive. ai
phantom-deps phantom-dep:@opentelemetry/instrumentation-express AI (phantom-deps): OTel config-referenced package; stable false positive. ai
publish-pattern rapid-publish AI (publish-pattern): Automated CI/CD pipeline with SLSA provenance; rapid successive publishes are expected. ai
phantom-deps phantom-dep:@sentry/opentelemetry AI (phantom-deps): OTel config-referenced package; stable false positive. ai
phantom-deps phantom-dep:@types/ws AI (phantom-deps): TypeScript type package loaded by convention; stable false positive. ai
phantom-deps phantom-dep:bufferutil AI (phantom-deps): Optional ws peer dep referenced in config; stable false positive. ai
phantom-deps phantom-dep:supervisor AI (phantom-deps): Process manager referenced in config; stable false positive. ai
phantom-deps phantom-dep:typescript AI (phantom-deps): Build tooling referenced in config; stable false positive. ai

Versions (showing 15 of 15)

Version Deps Published
47.1.5 102 / 16
47.1.4 102 / 16
47.1.3 102 / 16
47.1.2 102 / 16
47.1.0 102 / 16
47.0.9 102 / 16
47.0.4 102 / 16
46.2.3 102 / 18
45.1.21 102 / 18
45.1.8 101 / 18
45.1.7 101 / 18
45.1.3 101 / 18
45.1.2 101 / 18
44.3.0 100 / 18
43.3.7 96 / 18

v47.1.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v47.1.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v47.1.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v47.1.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v47.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v47.0.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v47.0.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v46.2.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v45.1.21

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v45.1.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v45.1.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v45.1.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v45.1.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v43.3.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.