@cloud-copilot/iam-collect
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions CI publishing with SLSA attestation; consistent with legitimate automation migration for this package. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New dep is an official AWS SDK client (@aws-sdk/client-config-service); fits the package's pattern of adding AWS service coverage. | ai | |
| dependencies | unvetted-dep:@cloud-copilot/log | AI (dependencies): Same-org dependency from cloud-copilot; stable pattern across all versions of this package. | ai | |
| dependencies | unvetted-dep:@aws-sdk/client-glacier | AI (dependencies): Official AWS SDK v3 client; well-known and trusted. | ai | |
| dependencies | unvetted-dep:@cloud-copilot/cli | AI (dependencies): Same-org dependency from cloud-copilot; stable pattern across all versions of this package. | ai | |
| dependencies | unvetted-dep:@aws-sdk/client-api-gateway | AI (dependencies): Official AWS SDK v3 client; well-known and trusted. | ai | |
| dependencies | unvetted-dep:@aws-sdk/client-s3-control | AI (dependencies): Official AWS SDK v3 client; well-known and trusted. | ai | |
| dependencies | unvetted-dep:@cloud-copilot/job | AI (dependencies): Same-org dependency from cloud-copilot; stable pattern across all versions of this package. | ai |
Versions (showing 6 of 206)
| Version | Deps | Published |
|---|---|---|
| 0.1.6 | 10 / 12 | |
| 0.1.5 | 10 / 12 | |
| 0.1.4 | 10 / 12 | |
| 0.1.3 | 10 / 12 | |
| 0.1.2 | 0 / 12 | |
| 0.1.1 | 0 / 5 |
v0.1.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.