@dcloudio/types
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Versions (showing 14 of 14)
| Version | Deps | Published |
|---|---|---|
| 3.4.32 | 0 / 6 | |
| 3.4.31 | 0 / 6 | |
| 3.4.30 | 0 / 6 | |
| 3.4.29 | 0 / 6 | |
| 3.4.19 | 0 / 6 | |
| 3.4.18 | 0 / 6 | |
| 3.4.16 | 0 / 6 | |
| 3.4.15 | 0 / 6 | |
| 3.4.14 | 0 / 6 | |
| 3.4.13 | 0 / 6 | |
| 3.4.12 | 0 / 6 | |
| 3.4.11 | 0 / 6 | |
| 3.4.10 | 0 / 6 | |
| 3.4.9 | 0 / 6 |
v3.4.32
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.4.15
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (liuxiaohang) than the most recent previously approved version (wangyaqi) on 2025-04-22, but liuxiaohang is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.4.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.4.13
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (wangyaqi) than the most recent previously approved version (otto_j) on 2024-10-19, but wangyaqi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.4.12
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (otto_j) than the most recent previously approved version (zhenyuwang) on 2024-07-18, but otto_j is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.4.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.4.10
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.4.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.