← Home

@bilig/headless

WorkPaper spreadsheet workbook facade for bilig with HyperFormula-style workflows.

54
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

kalmyk

Keywords

agent-toolsai-agentsexcelexcel-formulasformula-engineformula-recalculationheadless-spreadsheethyperformulamcpmcp-servernodenode-spreadsheetnode-spreadsheet-formulasserver-side-formula-enginespreadsheet-agentspreadsheet-automationspreadsheet-enginespreadsheet-formula-enginespreadsheet-formulastypescriptworkbook-agentworkbook-apiworkpaperxlsx

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff large-new-source-files AI (source-diff): New files reflect XLSX/WASM feature addition with new subpath export; consistent with package purpose. ai
source-diff source-size-tripled AI (source-diff): Size increase driven by XLSX/WASM support addition; no obfuscation or injected payloads detected. ai
provenance publisher-changed AI (provenance): Transition from kalmyk to GitHub Actions is a legitimate CI/CD migration, confirmed by SLSA provenance attestation. ai
provenance missing-githead AI (provenance): Package has SLSA provenance attestation which supersedes gitHead as a supply chain integrity signal. ai
provenance no-provenance AI (provenance): Package is not yet using CI/CD provenance; no other risk signals present. ai
dependencies unvetted-dep:@bilig/core AI (dependencies): Sibling package in the same @bilig monorepo, consistently versioned; not an independent third-party risk. ai

Versions (showing 54 of 269)

Version Deps Published
0.1.53 3 / 0
0.1.52 3 / 0
0.1.51 3 / 0
0.1.50 3 / 0
0.1.49 3 / 0
0.1.48 3 / 0
0.1.47 3 / 0
0.1.46 3 / 0
0.1.45 3 / 0
0.1.44 3 / 0
0.1.43 3 / 0
0.1.42 3 / 0
0.1.41 3 / 0
0.1.40 3 / 0
0.1.39 3 / 0
0.1.38 3 / 0
0.1.37 3 / 0
0.1.36 3 / 0
0.1.35 3 / 0
0.1.34 3 / 0
0.1.33 3 / 0
0.1.32 3 / 0
0.1.31 3 / 0
0.1.30 3 / 0
0.1.29 3 / 0
0.1.28 3 / 0
0.1.27 3 / 0
0.1.26 3 / 0
0.1.25 3 / 0
0.1.24 3 / 0
0.1.23 3 / 0
0.1.22 3 / 0
0.1.21 3 / 0
0.1.20 3 / 0
0.1.19 3 / 0
0.1.18 3 / 0
0.1.17 3 / 0
0.1.16 3 / 0
0.1.15 3 / 0
0.1.14 3 / 0
0.1.13 3 / 0
0.1.12 3 / 0
0.1.11 3 / 0
0.1.10 3 / 0
0.1.9 3 / 0
0.1.8 3 / 0
0.1.7 3 / 0
0.1.6 3 / 0
0.1.5 3 / 0
0.1.4 3 / 0
0.1.3 3 / 0
0.1.2 3 / 0
0.1.1 3 / 0
0.1.0 3 / 0

v0.1.39

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.38

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.37

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.35

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.34

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.33

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.32

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.30

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.29

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.