@conform-to/dom
A set of opinionated helpers built on top of the Constraint Validation API
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): Metadata-only publish-env change on a trusted high-download package; no code changes. | ai | |
| provenance | no-provenance | AI (provenance): Absence of attestation is not a risk signal for this established package. | ai | |
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions CI/CD publishing is documented by SLSA attestation; stable pattern for this package going forward. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped form-validation package; no relation to joi. Levenshtein match is coincidental. | ai | |
| typosquat | typosquat.levenshtein:koa | AI (typosquat): Scoped form-validation package; no relation to koa. Levenshtein match is coincidental. | ai | |
| typosquat | typosquat.levenshtein:zod | AI (typosquat): Scoped form-validation package; no relation to zod. Levenshtein match is coincidental. | ai | |
| typosquat | typosquat.levenshtein:got | AI (typosquat): Scoped form-validation package; no relation to got. Levenshtein match is coincidental. | ai | |
| typosquat | typosquat.levenshtein:jsdom | AI (typosquat): Scoped form-validation package; no relation to jsdom. Levenshtein match is coincidental. | ai |
Versions (showing 46 of 46)
| Version | Deps | Published |
|---|---|---|
| 1.20.1 | 0 / 10 | |
| 1.20.0 | 0 / 10 | |
| 1.19.4 | 0 / 10 | |
| 1.19.3 | 0 / 10 | |
| 1.19.2 | 0 / 7 | |
| 1.19.1 | 0 / 7 | |
| 1.19.0 | 0 / 7 | |
| 1.18.0 | 0 / 7 | |
| 1.17.1 | 0 / 7 | |
| 1.17.0 | 0 / 7 | |
| 1.16.0 | 0 / 7 | |
| 1.15.1 | 0 / 7 | |
| 1.15.0 | 0 / 7 | |
| 1.14.1 | 0 / 7 | |
| 1.14.0 | 0 / 7 | |
| 1.13.3 | 0 / 7 | |
| 1.13.2 | 0 / 7 | |
| 1.13.1 | 0 / 7 | |
| 1.13.0 | 0 / 7 | |
| 1.12.1 | 0 / 7 | |
| 1.12.0 | 0 / 7 | |
| 1.11.0 | 0 / 7 | |
| 1.10.1 | 0 / 7 | |
| 1.10.0 | 0 / 7 | |
| 1.9.1 | 0 / 7 | |
| 1.9.0 | 0 / 7 | |
| 1.8.2 | 0 / 7 | |
| 1.8.1 | 0 / 7 | |
| 1.8.0 | 0 / 7 | |
| 1.7.2 | 0 / 7 | |
| 1.7.1 | 0 / 7 | |
| 1.7.0 | 0 / 7 | |
| 1.6.1 | 0 / 7 | |
| 1.6.0 | 0 / 7 | |
| 1.5.1 | 0 / 7 | |
| 1.5.0 | 0 / 7 | |
| 1.4.0 | 0 / 7 | |
| 1.3.0 | 0 / 7 | |
| 1.2.2 | 0 / 7 | |
| 1.2.1 | 0 / 7 | |
| 1.2.0 | 0 / 7 | |
| 1.1.5 | 0 / 7 | |
| 1.1.4 | 0 / 7 | |
| 1.1.3 | 0 / 7 | |
| 1.1.2 | 0 / 0 | |
| 1.1.1 | 0 / 0 |
v1.20.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.20.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: edmundhung.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: edmundhung.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.2
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: edmundhung.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: edmundhung.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: edmundhung.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.5
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: edmundhung.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.