← Home

@coveo/bueno

[![npm version](https://badge.fury.io/js/@coveo%2Fbueno.svg)](https://badge.fury.io/js/@coveo%2Fbueno)

35
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

coveo-organizationcoveoitnpmcoveopixheloa-npmcoveo

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance slsa-provenance AI (provenance): Package publishes via GitHub Actions with SLSA v1 attestation; this is the expected and stable publish flow going forward. ai
provenance publisher-changed AI (provenance): Transition from individual npmcoveo account to GitHub Actions CI/CD is a legitimate pipeline modernization for the Coveo org; stable going forward. ai
provenance missing-githead AI (provenance): SLSA provenance attestation provides equivalent or stronger source traceability; missing gitHead is expected when publishing via GitHub Actions with Sigstore. ai
maintainer-change maintainer-added AI (maintainer-change): oa-npmcoveo is a Coveo service account replacing individual maintainers as part of CI/CD automation; legitimate organizational change. ai
maintainer-change maintainer-removed AI (maintainer-change): Removal of individual maintainers in favor of a service account is consistent with Coveo's pipeline modernization; not a takeover signal. ai
publish-pattern dormant-publish AI (publish-pattern): Dormancy followed by publish is explained by the organizational pipeline migration; SLSA attestation confirms legitimate CI origin. ai

Versions (showing 35 of 35)

Version Deps Published
1.1.9 0 / 1
1.1.8 0 / 1
1.1.7 0 / 1
1.1.6 0 / 1
1.1.5 0 / 1
1.1.4 0 / 1
1.1.3 0 / 1
1.1.2 0 / 1
1.1.1 0 / 1
1.1.0 0 / 1
1.0.24 0 / 1
1.0.23 0 / 1
1.0.22 0 / 2
1.0.21 0 / 2
1.0.20 0 / 2
1.0.19 0 / 2
1.0.18 0 / 2
1.0.17 0 / 2
1.0.16 0 / 2
1.0.15 0 / 2
1.0.14 0 / 2
1.0.13 0 / 2
1.0.12 0 / 2
1.0.11 0 / 2
1.0.10 0 / 2
1.0.9 0 / 2
1.0.8 0 / 2
1.0.7 0 / 3
1.0.6 0 / 3
1.0.5 0 / 3
1.0.4 0 / 3
1.0.3 0 / 3
1.0.2 0 / 3
1.0.1 0 / 3
1.0.0 0 / 3

v1.0.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.