← Home

@contentauth/c2pa-node

4
Versions
License
Yes
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

emenschandyp-adobecolmurph-adobeale-adobecaiopensrc

Keywords

c2pa

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
maintainer-change maintainer-added AI (maintainer-change): New maintainers match Adobe authors in package.json; publish moved to trusted CI/CD provenance. ai
phantom-deps phantom-dep:debug AI (phantom-deps): Used via config/postinstall tooling, not a security concern. ai
phantom-deps phantom-dep:cargo-cp-artifact AI (phantom-deps): Used by native build tooling, not directly imported by design. ai
install-scripts install-script:postinstall AI (install-scripts): Native Rust binding; postinstall downloads prebuilt binaries — documented pattern for this package. ai
source-diff source-size-tripled AI (source-diff): Growth from 2KB to 140KB reflects addition of Cargo.lock and binding source files, not injected payloads. ai
publish-pattern new-deps-added AI (publish-pattern): All new deps (node-fetch, unzipper, cli-progress, etc.) support the prebuilt binary download workflow; consistent with package purpose. ai
source-diff large-new-source-files AI (source-diff): Major version jump adding full Rust binding infrastructure; size increase is expected. ai

Versions (showing 4 of 4)

Version Deps Published
0.6.1 9 / 24
0.6.0 9 / 24
0.5.5 9 / 24
0.1.0 1 / 20

v0.6.1

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: caiopensrc → GitHub Actions (on 2026-07-16, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (caiopensrc) on 2026-07-16, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.