← Home

@davidsneighbour/tools

Tooling packages for use in @davidsneighbour projects.

6
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

davidsneighbour

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:ncp AI (phantom-deps): Tooling meta-package; deps are CLI tools invoked via scripts, not imported. ai
phantom-deps phantom-dep:debug AI (phantom-deps): Tooling meta-package; deps are CLI tools invoked via scripts, not imported. ai
phantom-deps phantom-dep:dotenv AI (phantom-deps): Tooling meta-package; deps are CLI tools invoked via scripts, not imported. ai
phantom-deps phantom-dep:rimraf AI (phantom-deps): Tooling meta-package; deps are CLI tools invoked via scripts, not imported. ai
phantom-deps phantom-dep:semver AI (phantom-deps): Tooling meta-package; deps are CLI tools invoked via scripts, not imported. ai
phantom-deps phantom-dep:wireit AI (phantom-deps): Tooling meta-package; deps are CLI tools invoked via scripts, not imported. ai
phantom-deps phantom-dep:fixpack AI (phantom-deps): Tooling meta-package; deps are CLI tools invoked via scripts, not imported. ai
phantom-deps phantom-dep:cross-env AI (phantom-deps): Tooling meta-package; deps are CLI tools invoked via scripts, not imported. ai
phantom-deps phantom-dep:deepmerge AI (phantom-deps): Tooling meta-package; deps are CLI tools invoked via scripts, not imported. ai
phantom-deps phantom-dep:npm-watch AI (phantom-deps): Tooling meta-package; deps are CLI tools invoked via scripts, not imported. ai
phantom-deps phantom-dep:node-fetch AI (phantom-deps): Tooling meta-package; deps are CLI tools invoked via scripts, not imported. ai
phantom-deps phantom-dep:secretlint AI (phantom-deps): Tooling meta-package; deps are CLI tools invoked via scripts, not imported. ai
phantom-deps phantom-dep:npm-run-all2 AI (phantom-deps): Tooling meta-package; deps are CLI tools invoked via scripts, not imported. ai
phantom-deps phantom-dep:@j9t/obsohtml AI (phantom-deps): Tooling meta-package; deps are CLI tools invoked via scripts, not imported. ai
phantom-deps phantom-dep:lockfile-lint AI (phantom-deps): Tooling meta-package; deps are CLI tools invoked via scripts, not imported. ai
phantom-deps phantom-dep:@clack/prompts AI (phantom-deps): Tooling meta-package; deps are CLI tools invoked via scripts, not imported. ai
phantom-deps phantom-dep:npm-check-updates AI (phantom-deps): Tooling meta-package; deps are CLI tools invoked via scripts, not imported. ai
phantom-deps phantom-dep:npm-package-json-lint AI (phantom-deps): Tooling meta-package; deps are CLI tools invoked via scripts, not imported. ai
phantom-deps phantom-dep:@secretlint/secretlint-rule-openai AI (phantom-deps): Tooling meta-package; deps are CLI tools invoked via scripts, not imported. ai
phantom-deps phantom-dep:@secretlint/secretlint-rule-pattern AI (phantom-deps): Tooling meta-package; deps are CLI tools invoked via scripts, not imported. ai

Versions (showing 6 of 6)

Version Deps Published
2026.0.5 25 / 0
2026.0.4 25 / 0
2026.0.3 25 / 0
2026.0.2 25 / 0
2026.0.1 25 / 0
2025.3.9 25 / 0

v2026.0.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2026.0.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2026.0.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2026.0.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2026.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2025.3.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.