@comet/cms-api
Comet CMS API package
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | large-new-source-files | AI (source-diff): New files correspond to added tiptap-based editor feature, not injected code. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): Tiptap editor extensions are well-known packages added for a feature, not supply-chain risk. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): Monorepo lockstep releases publish quickly; consistent with trusted publisher history. | ai | |
| phantom-deps | phantom-dep:@nestjs/jwt | AI (phantom-deps): NestJS module loaded by convention, not direct import. | ai | |
| phantom-deps | phantom-dep:passport | AI (phantom-deps): Framework-level dep loaded via NestJS convention, not direct import. | ai | |
| phantom-deps | phantom-dep:@smithy/node-http-handler | AI (phantom-deps): AWS SDK transitive dep pinned for known issue; loaded by convention. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Standard Basic Auth header parsing; not hiding payloads. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Loads migration files from a known directory; controlled input, not arbitrary user data. | ai | |
| semgrep | semgrep:hex-decode | AI (semgrep): HMAC key/salt hex decoding for imgproxy URL signing; legitimate crypto use. | ai |
Versions (showing 66 of 66)
| Version | Deps | Published |
|---|---|---|
| 9.2.2 | 44 / 46 | |
| 9.2.1 | 44 / 46 | |
| 9.2.0 | 44 / 46 | |
| 9.1.1 | 44 / 46 | |
| 9.1.0 | 44 / 46 | |
| 9.0.1 | 44 / 46 | |
| 9.0.0 | 44 / 46 | |
| 8.28.2 | 39 / 46 | |
| 8.28.1 | 39 / 46 | |
| 8.28.0 | 39 / 46 | |
| 8.27.1 | 39 / 46 | |
| 8.27.0 | 39 / 46 | |
| 8.26.0 | 39 / 46 | |
| 8.25.1 | 39 / 46 | |
| 8.25.0 | 39 / 46 | |
| 8.24.5 | 39 / 46 | |
| 8.24.4 | 39 / 46 | |
| 8.24.3 | 39 / 46 | |
| 8.24.2 | 39 / 46 | |
| 8.24.1 | 39 / 46 | |
| 8.24.0 | 38 / 46 | |
| 8.23.4 | 38 / 46 | |
| 8.23.3 | 38 / 46 | |
| 8.23.2 | 38 / 46 | |
| 8.23.1 | 38 / 46 | |
| 8.23.0 | 38 / 46 | |
| 8.22.0 | 38 / 46 | |
| 8.21.1 | 38 / 46 | |
| 8.21.0 | 38 / 46 | |
| 8.20.4 | 38 / 46 | |
| 8.20.3 | 38 / 46 | |
| 8.20.2 | 38 / 46 | |
| 8.20.1 | 38 / 46 | |
| 8.20.0 | 38 / 46 | |
| 8.19.0 | 38 / 46 | |
| 8.18.0 | 38 / 46 | |
| 8.17.1 | 38 / 46 | |
| 8.17.0 | 38 / 46 | |
| 8.16.0 | 38 / 46 | |
| 8.15.0 | 38 / 46 | |
| 8.14.0 | 38 / 46 | |
| 8.13.0 | 38 / 46 | |
| 8.12.0 | 37 / 45 | |
| 8.11.1 | 37 / 45 | |
| 8.11.0 | 37 / 45 | |
| 8.10.0 | 37 / 45 | |
| 8.9.0 | 37 / 44 | |
| 8.8.0 | 37 / 44 | |
| 8.7.1 | 37 / 44 | |
| 8.7.0 | 37 / 44 | |
| 8.6.0 | 38 / 44 | |
| 8.5.2 | 38 / 44 | |
| 8.5.1 | 38 / 44 | |
| 8.5.0 | 39 / 44 | |
| 8.4.2 | 39 / 44 | |
| 8.4.0 | 39 / 44 | |
| 8.3.0 | 39 / 44 | |
| 8.2.0 | 39 / 44 | |
| 8.1.1 | 39 / 44 | |
| 8.1.0 | 39 / 44 | |
| 8.0.0 | 39 / 44 | |
| 7.26.0 | 51 / 44 | |
| 7.25.15 | 51 / 44 | |
| 7.25.14 | 50 / 44 | |
| 7.25.13 | 50 / 44 | |
| 7.25.12 | 50 / 44 |
v9.2.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.2.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.2.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.1.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.1.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.0.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.0.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.28.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.28.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.28.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.27.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.27.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.26.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.25.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.25.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.26.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.