@contentauth/c2pa-node
4
Versions
—
License
Yes
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
emenschandyp-adobecolmurph-adobeale-adobecaiopensrc
Keywords
c2pa
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-added | AI (maintainer-change): New maintainers match Adobe authors in package.json; publish moved to trusted CI/CD provenance. | ai | |
| phantom-deps | phantom-dep:debug | AI (phantom-deps): Used via config/postinstall tooling, not a security concern. | ai | |
| phantom-deps | phantom-dep:cargo-cp-artifact | AI (phantom-deps): Used by native build tooling, not directly imported by design. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Native Rust binding; postinstall downloads prebuilt binaries — documented pattern for this package. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Growth from 2KB to 140KB reflects addition of Cargo.lock and binding source files, not injected payloads. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): All new deps (node-fetch, unzipper, cli-progress, etc.) support the prebuilt binary download workflow; consistent with package purpose. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Major version jump adding full Rust binding infrastructure; size increase is expected. | ai |
Versions (showing 4 of 4)
| Version | Deps | Published |
|---|---|---|
| 0.6.1 | 9 / 24 | |
| 0.6.0 | 9 / 24 | |
| 0.5.5 | 9 / 24 | |
| 0.1.0 | 1 / 20 |
v0.6.1
2 findings
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
INFO
Publisher changed: caiopensrc → GitHub Actions (on 2026-07-16, now via trusted publisher with provenance)
provenance
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (caiopensrc) on 2026-07-16, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.