@bifold/core
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| typosquat | typosquat.levenshtein:cors | AI (typosquat): @bifold/core is the OpenWallet Foundation bifold-wallet package; no relation to the cors package. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Standard URL-safe base64 decoding in a helper utility; no obfuscation or exfiltration pattern. | ai | |
| phantom-deps | phantom-dep:@types/base-64 | AI (phantom-deps): Type-only package listed in dependencies; not directly imported at runtime by convention. | ai | |
| phantom-deps | phantom-dep:@openwallet-foundation/askar-shared | AI (phantom-deps): Referenced in config files as documented; stable false positive for this package. | ai |
Versions (showing 43 of 43)
| Version | Deps | Published |
|---|---|---|
| 3.0.19 | 3 / 111 | |
| 3.0.18 | 3 / 111 | |
| 3.0.17 | 3 / 111 | |
| 3.0.16 | 3 / 111 | |
| 3.0.15 | 3 / 111 | |
| 3.0.14 | 3 / 111 | |
| 3.0.13 | 3 / 111 | |
| 3.0.12 | 3 / 111 | |
| 3.0.11 | 3 / 111 | |
| 3.0.10 | 3 / 109 | |
| 3.0.9 | 3 / 109 | |
| 3.0.8 | 3 / 109 | |
| 3.0.7 | 3 / 109 | |
| 3.0.6 | 3 / 109 | |
| 3.0.5 | 3 / 109 | |
| 3.0.4 | 3 / 109 | |
| 3.0.3 | 3 / 109 | |
| 3.0.0 | 3 / 108 | |
| 2.12.13 | 1 / 107 | |
| 2.12.12 | 1 / 107 | |
| 2.12.11 | 1 / 107 | |
| 2.12.10 | 1 / 107 | |
| 2.12.9 | 1 / 107 | |
| 2.12.8 | 1 / 107 | |
| 2.12.7 | 1 / 107 | |
| 2.12.6 | 1 / 107 | |
| 2.12.5 | 1 / 107 | |
| 2.12.4 | 1 / 108 | |
| 2.12.3 | 1 / 108 | |
| 2.12.2 | 1 / 108 | |
| 2.12.1 | 1 / 108 | |
| 2.12.0 | 1 / 108 | |
| 2.11.12 | 1 / 113 | |
| 2.11.11 | 1 / 113 | |
| 2.11.10 | 1 / 112 | |
| 2.11.9 | 1 / 112 | |
| 2.11.8 | 1 / 111 | |
| 2.11.7 | 1 / 111 | |
| 2.11.6 | 1 / 111 | |
| 2.11.5 | 1 / 114 | |
| 2.11.4 | 1 / 113 | |
| 2.11.3 | 1 / 113 | |
| 2.11.2 | 1 / 113 |
v3.0.19
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.0.18
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.0.17
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.12.13
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.12.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.12.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.12.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.12.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.12.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.12.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.12.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.12.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.12.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.12.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.12.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.12.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.12.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.11.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.11.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.11.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.11.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.11.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.11.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.11.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.11.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.11.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.11.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.11.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.