← Home

@checkstack/catalog-common

51
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

enyineer

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): Established internal org package with strong publisher track record; missing gitHead alone is insufficient to block. ai
publish-pattern new-deps-added AI (publish-pattern): New dep is same-org @checkstack/auth-common, not directly imported; low supply-chain risk for this package. ai
provenance no-provenance AI (provenance): Internal monorepo package; provenance not configured for this scope. ai
npm-metadata no-description AI (npm-metadata): Internal monorepo package; missing description is expected. ai
bogus-package bogus-package AI (bogus-package): Internal monorepo package; missing metadata is expected for scoped workspace packages. ai
phantom-deps phantom-dep:@checkstack/auth-common AI (phantom-deps): Same-org scoped package; phantom-dep heuristic unreliable for TS-first packages that re-export types. ai
phantom-deps phantom-dep:@orpc/contract AI (phantom-deps): Likely used in type-level or config context; false positive for TS-first package. ai

Versions (showing 51 of 53)

View all versions
Version Deps Published
2.8.1 7 / 3
2.8.0 7 / 3
2.7.3 7 / 3
2.7.2 7 / 3
2.7.1 7 / 3
2.7.0 7 / 3
2.6.3 7 / 3
2.6.2 7 / 3
2.6.1 7 / 3
2.6.0 7 / 3
2.5.0 7 / 3
2.4.3 6 / 3
2.4.2 6 / 3
2.4.1 6 / 3
2.4.0 6 / 3
2.3.6 6 / 3
2.3.5 6 / 3
2.3.4 6 / 3
2.3.3 6 / 3
2.3.2 6 / 3
2.3.1 6 / 3
2.3.0 6 / 3
2.2.3 6 / 3
2.2.2 6 / 3
2.2.1 6 / 3
2.2.0 6 / 3
2.1.0 6 / 3
2.0.1 6 / 3
2.0.0 6 / 3
1.5.3 5 / 3
1.5.2 5 / 3
1.5.1 5 / 3
1.5.0 5 / 3
1.4.1 5 / 3
1.4.0 5 / 3
1.3.1 5 / 3
1.3.0 5 / 3
1.2.11 5 / 3
1.2.10 5 / 3
1.2.9 5 / 3
1.2.8 5 / 3
1.2.7 5 / 3
1.2.6 5 / 3
1.2.5 4 / 3
1.2.4 4 / 3
1.2.3 4 / 3
1.2.2 4 / 3
1.2.1 4 / 3
1.2.0 4 / 3
1.1.0 4 / 3
1.0.0 4 / 3

v2.8.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.8.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.7.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.7.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.7.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.7.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.6.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.6.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.6.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.6.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.