@codingame/monaco-vscode-files-service-override
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions publisher is confirmed legitimate by SLSA/Sigstore attestation on this package. | ai | |
| dependencies | unvetted-dep:@codingame/monaco-vscode-d392702e-4ad7-5904-a915-f6063284cf14-common | AI (dependencies): Internal monorepo sub-package from CodinGame; same versioning pattern across all releases. | ai | |
| dependencies | unvetted-dep:@codingame/monaco-vscode-1f37b5fb-f500-54d2-b98a-d12d100cafca-common | AI (dependencies): Internal monorepo split package from CodinGame; consistent pattern across all versions. | ai | |
| dependencies | unvetted-dep:@codingame/monaco-vscode-2f06fe84-148e-5e6b-a7ca-c7989c5f128a-common | AI (dependencies): Internal monorepo sub-package from same publisher/version; stable pattern across all releases. | ai | |
| dependencies | unvetted-dep:@codingame/monaco-vscode-60014c9d-b815-501d-83a9-4b08725c2ec2-common | AI (dependencies): Internal monorepo sub-package from same publisher/version; stable pattern across all releases. | ai | |
| dependencies | unvetted-dep:@codingame/monaco-vscode-cea4d01f-6526-5c2f-8b09-b168fead499f-common | AI (dependencies): Internal monorepo sub-package from same publisher/version; stable pattern across all releases. | ai | |
| dependencies | unvetted-dep:@codingame/monaco-vscode-caeb744c-8e3f-5c11-80fb-0f057d24d544-common | AI (dependencies): Internal monorepo sub-package from same publisher/version; stable pattern across all releases. | ai | |
| dependencies | unvetted-dep:@codingame/monaco-vscode-0c06bfba-d24d-5c4d-90cd-b40cefb7f811-common | AI (dependencies): Internal monorepo sub-package from same publisher/version; stable pattern across all releases. | ai | |
| dependencies | unvetted-dep:@codingame/monaco-vscode-15626ec7-b165-51e1-8caf-7bcc2ae9b95a-common | AI (dependencies): Internal monorepo sub-package from same publisher/version; stable pattern across all releases. | ai | |
| provenance | no-provenance | AI (provenance): CodinGame org package with long history; lack of provenance is consistent across all their releases. | ai |
Versions (showing 51 of 71)
| Version | Deps | Published |
|---|---|---|
| 36.0.0 | 1 / 0 | |
| 35.0.3 | 1 / 0 | |
| 35.0.2 | 1 / 0 | |
| 35.0.1 | 1 / 0 | |
| 35.0.0 | 1 / 0 | |
| 34.1.3 | 1 / 0 | |
| 34.1.2 | 1 / 0 | |
| 34.1.1 | 1 / 0 | |
| 34.1.0 | 1 / 0 | |
| 34.0.3 | 1 / 0 | |
| 34.0.2 | 1 / 0 | |
| 34.0.1 | 1 / 0 | |
| 34.0.0 | 1 / 0 | |
| 33.0.9 | 1 / 0 | |
| 33.0.7 | 1 / 0 | |
| 33.0.6 | 1 / 0 | |
| 33.0.5 | 1 / 0 | |
| 32.0.2 | 1 / 0 | |
| 32.0.1 | 1 / 0 | |
| 32.0.0 | 1 / 0 | |
| 31.0.1 | 1 / 0 | |
| 31.0.0 | 1 / 0 | |
| 30.0.1 | 1 / 0 | |
| 30.0.0 | 1 / 0 | |
| 29.1.1 | 1 / 0 | |
| 29.1.0 | 1 / 0 | |
| 29.0.0 | 1 / 0 | |
| 28.4.1 | 1 / 0 | |
| 28.4.0 | 1 / 0 | |
| 28.3.1 | 1 / 0 | |
| 28.3.0 | 1 / 0 | |
| 28.2.0 | 1 / 0 | |
| 28.1.2 | 1 / 0 | |
| 28.1.1 | 1 / 0 | |
| 28.0.1 | 1 / 0 | |
| 28.0.0 | 1 / 0 | |
| 27.0.0 | 1 / 0 | |
| 26.2.2 | 1 / 0 | |
| 26.2.1 | 1 / 0 | |
| 26.2.0 | 1 / 0 | |
| 26.1.2 | 1 / 0 | |
| 26.1.1 | 1 / 0 | |
| 26.1.0 | 1 / 0 | |
| 26.0.1 | 1 / 0 | |
| 26.0.0 | 1 / 0 | |
| 25.1.2 | 1 / 0 | |
| 25.1.1 | 1 / 0 | |
| 25.1.0 | 1 / 0 | |
| 25.0.1 | 1 / 0 | |
| 25.0.0 | 1 / 0 | |
| 24.3.0 | 1 / 0 |
v36.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v35.0.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v35.0.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v35.0.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v35.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v34.1.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v34.1.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.