← Home

@capgo/native-purchases

In-app Subscriptions Made Easy

51
Versions
MPL-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

riderx

Keywords

capacitorpluginnativepurchasesIAPin-app purchasessubscriptions

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance slsa-provenance AI (provenance): CI/CD Sigstore attestation confirms legitimate build pipeline for this package. ai

Versions (showing 51 of 76)

View all versions
Version Deps Published
8.6.4 0 / 19
8.6.3 0 / 19
8.6.2 0 / 19
8.6.1 0 / 19
8.6.0 0 / 19
8.5.0 0 / 19
8.4.6 0 / 19
8.4.5 0 / 19
8.4.4 0 / 19
8.4.3 0 / 19
8.4.2 0 / 19
8.4.1 0 / 19
8.4.0 0 / 19
8.3.10 0 / 19
8.3.9 0 / 19
8.3.8 0 / 19
8.3.7 0 / 19
8.3.6 0 / 19
8.3.5 0 / 19
8.3.4 0 / 19
8.3.3 0 / 19
8.3.0 0 / 19
8.2.5 0 / 19
8.2.4 0 / 19
8.2.3 0 / 19
8.2.2 0 / 19
8.2.1 0 / 19
8.2.0 0 / 19
8.1.2 0 / 19
8.1.1 0 / 19
8.1.0 0 / 19
8.0.24 0 / 19
8.0.23 0 / 19
8.0.22 0 / 19
8.0.21 0 / 19
8.0.20 0 / 19
8.0.19 0 / 19
8.0.18 0 / 19
8.0.17 0 / 19
8.0.16 0 / 19
8.0.15 0 / 19
8.0.14 0 / 19
8.0.13 0 / 19
8.0.12 0 / 19
8.0.11 0 / 19
8.0.10 0 / 19
8.0.9 0 / 19
8.0.8 0 / 19
8.0.7 0 / 19
8.0.6 0 / 19
8.0.5 0 / 19

v8.6.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.6.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.6.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.6.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.