← Home

@comunica/actor-query-source-identify-hypermedia

9
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

joachimvhrubensworksrubenverborghdexagodjeswr

Keywords

comunicaactorquery-source-identifyhypermedia

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:sparqlalgebrajs AI (dependencies): sparqlalgebrajs is a well-known SPARQL algebra library in the RDF/JS ecosystem; stable dependency for this package. ai
dependencies unvetted-dep:rdf-streaming-store AI (dependencies): rdf-streaming-store is a standard RDF streaming utility; expected dependency for this Comunica actor. ai
dependencies unvetted-dep:@comunica/core AI (dependencies): Sibling Comunica monorepo package; unvetted status reflects registry lag, not risk. ai
dependencies unvetted-dep:@comunica/types AI (dependencies): Sibling Comunica monorepo package; unvetted status reflects registry lag, not risk. ai
dependencies unvetted-dep:@comunica/utils-algebra AI (dependencies): Sibling Comunica monorepo package; unvetted status reflects registry lag, not risk. ai
dependencies unvetted-dep:@comunica/utils-metadata AI (dependencies): Sibling Comunica monorepo package; unvetted status reflects registry lag, not risk. ai
dependencies unvetted-dep:@comunica/context-entries AI (dependencies): Sibling Comunica monorepo package; unvetted status reflects registry lag, not risk. ai
dependencies unvetted-dep:@comunica/utils-bindings-factory AI (dependencies): Sibling Comunica monorepo package; unvetted status reflects registry lag, not risk. ai
provenance no-provenance AI (provenance): Comunica monorepo does not publish with Sigstore provenance; stable false positive for this package. ai
dependencies unvetted-dep:@comunica/bus-merge-bindings-context AI (dependencies): Sibling Comunica monorepo package; unvetted status reflects registry lag, not risk. ai
dependencies unvetted-dep:@comunica/bus-rdf-metadata-accumulate AI (dependencies): Sibling Comunica monorepo package; unvetted status reflects registry lag, not risk. ai
dependencies unvetted-dep:@comunica/bus-rdf-resolve-hypermedia-links AI (dependencies): Sibling Comunica monorepo package; unvetted status reflects registry lag, not risk. ai
dependencies unvetted-dep:@comunica/bus-query-source-dereference-link AI (dependencies): Sibling Comunica monorepo package; unvetted status reflects registry lag, not risk. ai
dependencies unvetted-dep:@comunica/bus-rdf-resolve-hypermedia-links-queue AI (dependencies): Sibling Comunica monorepo package; unvetted status reflects registry lag, not risk. ai
dependencies unvetted-dep:@comunica/bus-query-source-identify AI (dependencies): Sibling Comunica monorepo package; unvetted status reflects registry lag, not risk. ai
dependencies unvetted-dep:asynciterator AI (dependencies): asynciterator is a well-known streaming library used throughout Comunica; not a risk. ai

Versions (showing 9 of 9)

Version Deps Published
5.2.3 15 / 0
5.2.2 15 / 0
5.2.0 15 / 0
5.1.3 15 / 0
5.1.0 15 / 0
5.0.3 15 / 0
5.0.2 15 / 0
5.0.0 15 / 0
4.5.0 22 / 0

v5.2.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.2.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.1.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.1.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.0.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.0.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.0.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.5.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.