← Home

@cubejs-backend/server

Cube.js all-in-one server

51
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

cubedevincstatsbotkeydunovmaxim_cube

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@cubejs-backend/dotenv AI (dependencies): Same-org scoped fork of dotenv; stable dependency pattern across Cube.js monorepo versions. ai
publish-pattern dormant-publish AI (publish-pattern): SLSA provenance attestation and no material changes vs prior version mitigate account-takeover concern for this established monorepo package. ai
phantom-deps phantom-dep:@oclif/config AI (phantom-deps): oclif config loaded via manifest/plugin system, not direct import; stable FP. ai
phantom-deps phantom-dep:codesandbox-import-utils AI (phantom-deps): Likely used indirectly via server-core or dynamic require; stable FP for this package. ai
phantom-deps phantom-dep:@cubejs-backend/cubestore-driver AI (phantom-deps): Same-org dep loaded dynamically; stable FP for this monorepo package. ai
phantom-deps phantom-dep:@oclif/plugin-help AI (phantom-deps): Declared as oclif plugin in package.json oclif.plugins; loaded by framework, not direct import. ai
phantom-deps phantom-dep:jsonwebtoken AI (phantom-deps): Used via oclif CLI/config indirection, not direct import; stable FP for this package. ai
typosquat typosquat.levenshtein:semver AI (typosquat): Legitimate Cube.js monorepo package; not a typosquat of semver — Levenshtein match is coincidental. ai
bogus-package bogus-package AI (bogus-package): Established Cube.js ecosystem package; sparse README is a documentation issue, not a spam/bogus signal. ai

Versions (showing 51 of 125)

View all versions
Version Deps Published
1.7.12 19 / 13
1.7.11 19 / 13
1.7.10 19 / 13
1.7.9 19 / 13
1.7.8 19 / 13
1.7.7 19 / 13
1.7.6 19 / 13
1.7.5 19 / 13
1.7.4 19 / 13
1.7.3 19 / 13
1.7.2 19 / 13
1.7.1 19 / 13
1.7.0 19 / 13
1.6.69 19 / 13
1.6.68 19 / 13
1.6.67 19 / 13
1.6.66 19 / 13
1.6.65 19 / 13
1.6.64 19 / 13
1.6.63 19 / 13
1.6.62 19 / 13
1.6.61 19 / 13
1.6.60 19 / 13
1.6.59 19 / 13
1.6.58 19 / 13
1.6.57 19 / 13
1.6.56 19 / 13
1.6.55 19 / 13
1.6.54 19 / 13
1.6.53 19 / 13
1.6.52 19 / 13
1.6.51 19 / 13
1.6.50 19 / 13
1.6.49 19 / 13
1.6.48 19 / 13
1.6.47 19 / 13
1.6.46 19 / 13
1.6.45 19 / 13
1.6.44 19 / 13
1.6.43 19 / 13
1.6.0 19 / 13
1.5.10 19 / 13
1.5.4 19 / 13
1.5.2 19 / 13
1.4.3 19 / 13
1.3.85 19 / 13
1.3.84 19 / 13
1.3.83 19 / 13
1.3.10 19 / 13
1.3.9 19 / 13
1.3.8 19 / 12

v1.7.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.7.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.7.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.7.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.7.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.7.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.7.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.7.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.7.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.7.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.7.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.7.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.7.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.6.69

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.6.68

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.6.67

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.6.66

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.6.65

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.6.64

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.