← Home

@cloudflare/workerd-darwin-arm64

👷 workerd for macOS ARM 64-bit, Cloudflare's JavaScript/Wasm Runtime

100
Versions
Apache-2.0
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures gitHead linked

Maintainers

cf-ci-writedash_service_accountwrangler-publishercfprivengcf-npm-publish

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
npm-metadata bundled-binaries AI (npm-metadata): workerd runtime binary is the package's stated function; stable across platform-binary releases. ai
bogus-package bogus-package AI (bogus-package): Platform-specific binary distribution package from Cloudflare workerd. No deps, tiny payload, and minimal README are expected characteristics of OS/CPU-scoped binary packages. Stable false positive for this package. ai

Versions (showing 100 of 447)

Version Deps Published
1.20260727.1 0 / 0
1.20260726.1 0 / 0
1.20260724.1 0 / 0
1.20260723.1 0 / 0
1.20260722.1 0 / 0
1.20260721.1 0 / 0
1.20260719.1 0 / 0
1.20260718.1 0 / 0
1.20260717.1 0 / 0
1.20260715.1 0 / 0
1.20260714.1 0 / 0
1.20260713.1 0 / 0
1.20260712.1 0 / 0
1.20260711.1 0 / 0
1.20260710.1 0 / 0
1.20260707.1 0 / 0
1.20260705.1 0 / 0
1.20260703.1 0 / 0
1.20260702.1 0 / 0
1.20260701.1 0 / 0
1.20260630.1 0 / 0
1.20260629.1 0 / 0
1.20260628.1 0 / 0
1.20260626.1 0 / 0
1.20260625.1 0 / 0
1.20260624.1 0 / 0
1.20260621.1 0 / 0
1.20260619.1 0 / 0
1.20260618.1 0 / 0
1.20260617.1 0 / 0
1.20260616.1 0 / 0
1.20260615.1 0 / 0
1.20260613.1 0 / 0
1.20260612.1 0 / 0
1.20260611.1 0 / 0
1.20260610.1 0 / 0
1.20260609.1 0 / 0
1.20260608.1 0 / 0
1.20260607.1 0 / 0
1.20260606.1 0 / 0
1.20260605.1 0 / 0
1.20260604.1 0 / 0
1.20260603.1 0 / 0
1.20260602.1 0 / 0
1.20260531.1 0 / 0
1.20260530.1 0 / 0
1.20260528.1 0 / 0
1.20260527.1 0 / 0
1.20260526.1 0 / 0
1.20260525.1 0 / 0
1.20260523.1 0 / 0
1.20260521.1 0 / 0
1.20260519.1 0 / 0
1.20260518.1 0 / 0
1.20260517.1 0 / 0
1.20260516.1 0 / 0
1.20260514.1 0 / 0
1.20260511.1 0 / 0
1.20260509.1 0 / 0
1.20260506.1 0 / 0
1.20260503.1 0 / 0
1.20260502.1 0 / 0
1.20260426.1 0 / 0
1.20260425.1 0 / 0
1.20260424.1 0 / 0
1.20260423.1 0 / 0
1.20260422.2 0 / 0
1.20260422.1 0 / 0
1.20260421.1 0 / 0
1.20260420.1 0 / 0
1.20260418.1 0 / 0
1.20260417.1 0 / 0
1.20260416.2 0 / 0
1.20260416.1 0 / 0
1.20260415.1 0 / 0
1.20260414.1 0 / 0
1.20260413.1 0 / 0
1.20260412.2 0 / 0
1.20260412.1 0 / 0
1.20260411.1 0 / 0
1.20260410.1 0 / 0
1.20260409.1 0 / 0
1.20260408.1 0 / 0
1.20260405.1 0 / 0
1.20260404.1 0 / 0
1.20260403.1 0 / 0
1.20260402.1 0 / 0
1.20260401.1 0 / 0
1.20260331.1 0 / 0
1.20260329.1 0 / 0
1.20260317.1 0 / 0
1.20260316.1 0 / 0
1.20260313.1 0 / 0
1.20260312.1 0 / 0
1.20260310.1 0 / 0
1.20260307.1 0 / 0
1.20260306.1 0 / 0
1.20260305.1 0 / 0
1.20260305.0 0 / 0
1.20260304.0 0 / 0
Showing 100 of 447 Next page →

v1.20260727.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.20260726.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.20260724.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.20260723.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.20260722.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • bin/workerd

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.20260721.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.20260719.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.20260718.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.20260717.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.20260715.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.20260714.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.20260713.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.20260712.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.20260711.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.20260710.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.20260707.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.20260705.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.20260703.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.20260702.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.20260701.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.20260630.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.20260629.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.