← Home

@coveo/create-atomic-result-component

Initialize a Coveo Atomic Result Component

17
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

coveo-organizationcoveoitnpmcoveopixheloa-npmcoveo

Keywords

atomicclicoveo

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Coveo migrated publishing to GitHub Actions CI with SLSA attestation; this is a legitimate org-wide CI/CD transition. ai

Versions (showing 17 of 17)

Version Deps Published
1.3.16 1 / 0
1.3.15 1 / 0
1.3.14 1 / 0
1.3.13 1 / 0
1.3.12 1 / 0
1.3.11 1 / 0
1.3.8 1 / 0
1.3.7 1 / 0
1.3.6 1 / 0
1.3.5 1 / 0
1.3.4 1 / 0
1.3.3 1 / 0
1.3.2 1 / 0
1.3.1 1 / 0
1.3.0 1 / 0
1.2.20 1 / 13
1.2.19 1 / 13

v1.2.20

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.19

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.