← Home

@computesdk/railway

Railway provider for ComputeSDK - simple cloud deployment for containerized sandboxes

47
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

heygarrison

Keywords

computesdkrailwaysandboxcode-executioncloudcomputeprovider

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:computesdk AI (dependencies): First-party sibling package in the computesdk monorepo; not an external unknown dependency. ai
dependencies unvetted-dep:@computesdk/provider AI (dependencies): First-party sibling package in the computesdk monorepo; not an external unknown dependency. ai
provenance no-provenance AI (provenance): Consistent across all 46 versions; no provenance is the norm for this package family. ai
phantom-deps phantom-dep:computesdk AI (phantom-deps): Same-org peer dependency referenced in config; not a direct import by design in this monorepo package. ai
phantom-deps phantom-dep:@computesdk/provider AI (phantom-deps): Same org scope; declared as runtime dep but used indirectly — stable false positive for this package. ai

Versions (showing 47 of 47)

Version Deps Published
2.0.1 3 / 8
1.2.2 2 / 8
1.2.1 2 / 8
1.2.0 2 / 8
1.1.42 2 / 8
1.1.41 2 / 8
1.1.40 2 / 8
1.1.39 2 / 8
1.1.38 2 / 8
1.1.37 2 / 8
1.1.36 2 / 8
1.1.35 2 / 8
1.1.34 2 / 8
1.1.33 2 / 8
1.1.32 2 / 8
1.1.31 2 / 8
1.1.29 2 / 8
1.1.28 2 / 8
1.1.26 2 / 8
1.1.25 2 / 8
1.1.24 2 / 8
1.1.23 2 / 8
1.1.22 2 / 8
1.1.21 2 / 8
1.1.20 2 / 8
1.1.19 2 / 8
1.1.18 2 / 8
1.1.17 2 / 8
1.1.15 2 / 8
1.1.14 2 / 8
1.1.13 2 / 8
1.1.12 2 / 8
1.1.11 2 / 8
1.1.10 2 / 8
1.1.9 2 / 8
1.1.8 2 / 8
1.1.7 2 / 8
1.1.6 1 / 8
1.1.5 1 / 8
1.1.4 1 / 8
1.1.3 1 / 8
1.1.2 1 / 8
1.1.1 1 / 8
1.1.0 1 / 8
1.0.2 1 / 8
1.0.1 1 / 8
1.0.0 1 / 8

v2.0.1

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: heygarrison → GitHub Actions (on 2026-07-20, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (heygarrison) on 2026-07-20, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.