← Home

@capgo/native-purchases

In-app Subscriptions Made Easy

76
Versions
MPL-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

riderx

Keywords

capacitorpluginnativepurchasesIAPin-app purchasessubscriptions

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance slsa-provenance AI (provenance): CI/CD Sigstore attestation confirms legitimate build pipeline for this package. ai

Versions (showing 76 of 76)

Version Deps Published
8.6.4 0 / 19
8.6.3 0 / 19
8.6.2 0 / 19
8.6.1 0 / 19
8.6.0 0 / 19
8.5.0 0 / 19
8.4.6 0 / 19
8.4.5 0 / 19
8.4.4 0 / 19
8.4.3 0 / 19
8.4.2 0 / 19
8.4.1 0 / 19
8.4.0 0 / 19
8.3.10 0 / 19
8.3.9 0 / 19
8.3.8 0 / 19
8.3.7 0 / 19
8.3.6 0 / 19
8.3.5 0 / 19
8.3.4 0 / 19
8.3.3 0 / 19
8.3.0 0 / 19
8.2.5 0 / 19
8.2.4 0 / 19
8.2.3 0 / 19
8.2.2 0 / 19
8.2.1 0 / 19
8.2.0 0 / 19
8.1.2 0 / 19
8.1.1 0 / 19
8.1.0 0 / 19
8.0.24 0 / 19
8.0.23 0 / 19
8.0.22 0 / 19
8.0.21 0 / 19
8.0.20 0 / 19
8.0.19 0 / 19
8.0.18 0 / 19
8.0.17 0 / 19
8.0.16 0 / 19
8.0.15 0 / 19
8.0.14 0 / 19
8.0.13 0 / 19
8.0.12 0 / 19
8.0.11 0 / 19
8.0.10 0 / 19
8.0.9 0 / 19
8.0.8 0 / 19
8.0.7 0 / 19
8.0.6 0 / 19
8.0.5 0 / 19
8.0.4 0 / 19
8.0.3 0 / 18
8.0.2 0 / 18
8.0.1 0 / 18
7.19.3 0 / 19
7.19.2 0 / 19
7.19.1 0 / 19
7.19.0 0 / 19
7.16.2 0 / 18
7.16.1 0 / 18
7.16.0 0 / 18
7.15.5 0 / 18
7.15.4 0 / 18
7.15.3 0 / 18
7.15.1 0 / 18
7.15.0 0 / 18
7.14.0 0 / 18
7.13.5 0 / 18
7.13.4 0 / 18
7.13.3 0 / 18
7.13.2 0 / 18
7.13.1 0 / 18
7.13.0 0 / 18
7.12.7 0 / 18
7.12.6 0 / 18

v8.6.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.6.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.6.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.6.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.19.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.19.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.19.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.19.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.