@cloudflare/workerd-darwin-arm64
👷 workerd for macOS ARM 64-bit, Cloudflare's JavaScript/Wasm Runtime
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | bundled-binaries | AI (npm-metadata): workerd runtime binary is the package's stated function; stable across platform-binary releases. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Platform-specific binary distribution package from Cloudflare workerd. No deps, tiny payload, and minimal README are expected characteristics of OS/CPU-scoped binary packages. Stable false positive for this package. | ai |
Versions (showing 51 of 447)
| Version | Deps | Published |
|---|---|---|
| 1.20260727.1 | 0 / 0 | |
| 1.20260726.1 | 0 / 0 | |
| 1.20260724.1 | 0 / 0 | |
| 1.20260723.1 | 0 / 0 | |
| 1.20260722.1 | 0 / 0 | |
| 1.20260721.1 | 0 / 0 | |
| 1.20260719.1 | 0 / 0 | |
| 1.20260718.1 | 0 / 0 | |
| 1.20260717.1 | 0 / 0 | |
| 1.20260715.1 | 0 / 0 | |
| 1.20260714.1 | 0 / 0 | |
| 1.20260713.1 | 0 / 0 | |
| 1.20260712.1 | 0 / 0 | |
| 1.20260711.1 | 0 / 0 | |
| 1.20260710.1 | 0 / 0 | |
| 1.20260707.1 | 0 / 0 | |
| 1.20260705.1 | 0 / 0 | |
| 1.20260703.1 | 0 / 0 | |
| 1.20260702.1 | 0 / 0 | |
| 1.20260701.1 | 0 / 0 | |
| 1.20260630.1 | 0 / 0 | |
| 1.20260629.1 | 0 / 0 | |
| 1.20260628.1 | 0 / 0 | |
| 1.20260626.1 | 0 / 0 | |
| 1.20260625.1 | 0 / 0 | |
| 1.20260624.1 | 0 / 0 | |
| 1.20260621.1 | 0 / 0 | |
| 1.20260619.1 | 0 / 0 | |
| 1.20260618.1 | 0 / 0 | |
| 1.20260617.1 | 0 / 0 | |
| 1.20260616.1 | 0 / 0 | |
| 1.20260615.1 | 0 / 0 | |
| 1.20260613.1 | 0 / 0 | |
| 1.20260612.1 | 0 / 0 | |
| 1.20260611.1 | 0 / 0 | |
| 1.20260610.1 | 0 / 0 | |
| 1.20260609.1 | 0 / 0 | |
| 1.20260608.1 | 0 / 0 | |
| 1.20260607.1 | 0 / 0 | |
| 1.20260606.1 | 0 / 0 | |
| 1.20260605.1 | 0 / 0 | |
| 1.20260604.1 | 0 / 0 | |
| 1.20260603.1 | 0 / 0 | |
| 1.20260602.1 | 0 / 0 | |
| 1.20260531.1 | 0 / 0 | |
| 1.20260530.1 | 0 / 0 | |
| 1.20260528.1 | 0 / 0 | |
| 1.20260527.1 | 0 / 0 | |
| 1.20260526.1 | 0 / 0 | |
| 1.20260525.1 | 0 / 0 | |
| 1.20260523.1 | 0 / 0 |
v1.20260727.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.20260726.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.20260724.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.20260723.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.20260722.1
2 findingsPackage contains compiled binaries that could be backdoors: • bin/workerd
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.20260721.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.20260719.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.20260718.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.20260717.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.20260715.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.20260714.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.20260713.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.20260712.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.20260711.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.20260710.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.20260707.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.20260705.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.20260703.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.20260702.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.20260701.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.20260630.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.20260629.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.