← Home

@cubejs-backend/crate-driver

Cube.js Crate database driver

51
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

cubedevincstatsbotkeydunovmaxim_cube

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Cube.js monorepo migrated publishing to GitHub Actions CI/CD with SLSA attestation; consistent across the org. ai
publish-pattern dormant-publish AI (publish-pattern): Dormancy reflects CI/CD pipeline change, not account takeover; SLSA attestation confirms legitimate publish. ai
bogus-package bogus-package AI (bogus-package): Monorepo sub-package; sparse README with links to main project docs is expected, not a spam indicator. ai
phantom-deps phantom-dep:@cubejs-backend/shared AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic is a stable false positive for this monorepo package. ai

Versions (showing 51 of 258)

View all versions
Version Deps Published
1.7.12 2 / 4
1.7.11 2 / 4
1.7.10 2 / 4
1.7.9 2 / 4
1.7.8 2 / 4
1.7.7 2 / 4
1.7.6 2 / 4
1.7.5 2 / 4
1.7.4 2 / 4
1.7.3 2 / 4
1.7.2 2 / 4
1.7.1 2 / 4
1.7.0 2 / 4
1.6.69 2 / 4
1.6.68 2 / 4
1.6.67 2 / 4
1.6.66 2 / 4
1.6.65 2 / 4
1.6.64 2 / 4
1.6.63 2 / 4
1.6.62 2 / 4
1.6.61 2 / 4
1.6.60 2 / 4
1.6.59 2 / 4
1.6.58 2 / 4
1.6.57 2 / 4
1.6.56 2 / 4
1.6.55 2 / 4
1.6.54 2 / 4
1.6.53 2 / 4
1.6.52 2 / 4
1.6.51 2 / 4
1.6.50 2 / 4
1.6.49 2 / 4
1.6.48 2 / 4
1.6.47 2 / 4
1.6.46 2 / 4
1.6.45 2 / 4
1.6.44 2 / 4
1.6.43 2 / 4
1.6.42 2 / 4
1.6.41 2 / 4
1.6.40 2 / 4
1.6.39 2 / 4
1.6.38 2 / 4
1.6.37 2 / 4
1.6.36 2 / 4
1.6.35 2 / 4
1.6.34 2 / 4
1.6.33 2 / 4
1.6.32 2 / 4

v1.7.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.7.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.7.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.7.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.7.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.7.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.7.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.7.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.7.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.7.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.7.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.7.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.7.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.6.69

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.6.68

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.6.67

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.6.66

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.6.65

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.