@cucumber/messages
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| install-behavior | install-behavior:native-compile | AI (install-behavior): 'make generate' is a codegen step in the Cucumber monorepo; not executed on consumer install. | ai | |
| npm-metadata | url-dep:@cucumber/biome-config | AI (npm-metadata): DevDependency pointing to Cucumber org's own biome-config repo; not a runtime concern. | ai | |
| source-diff | obfuscated-file:dist/messages.js | AI (source-diff): Standard tsc output with source maps; not obfuscated. Stable for this package. | ai | |
| source-diff | obfuscated-file:dist/TimeConversion.js | AI (source-diff): Standard tsc output with source maps; not obfuscated. Stable for this package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Established @cucumber scoped package with 7.4M downloads; low-value signals are false positives. | ai |
Versions (showing 19 of 19)
| Version | Deps | Published |
|---|---|---|
| 34.2.0 | 0 / 10 | |
| 34.1.0 | 0 / 10 | |
| 34.0.2 | 0 / 10 | |
| 34.0.1 | 0 / 10 | |
| 34.0.0 | 0 / 10 | |
| 33.0.4 | 0 / 10 | |
| 33.0.3 | 0 / 10 | |
| 33.0.2 | 0 / 10 | |
| 33.0.1 | 0 / 10 | |
| 32.3.1 | 2 / 7 | |
| 32.3.0 | 2 / 7 | |
| 32.2.0 | 2 / 7 | |
| 32.1.0 | 2 / 7 | |
| 32.0.1 | 2 / 7 | |
| 32.0.0 | 2 / 7 | |
| 31.2.0 | 2 / 7 | |
| 31.1.0 | 2 / 7 | |
| 31.0.1 | 2 / 7 | |
| 31.0.0 | 2 / 7 |
v34.2.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v34.1.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v34.0.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v34.0.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v34.0.0
2 findingsDetected raw native compilation in install lifecycle script(s): 'prepare'.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v33.0.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.