← Home

@deno/kv

10
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

rydivy-workdenobotbartlomieju

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:child-process-import AI (semgrep): musl/libc detection via ldd, standard native-binding pattern. ai
typosquat typosquat.levenshtein:pg AI (typosquat): False positive; unrelated package. ai
typosquat typosquat.levenshtein:qs AI (typosquat): False positive; unrelated package. ai
typosquat typosquat.levenshtein:koa AI (typosquat): Scoped @deno/kv name unrelated to koa; generic edit-distance false positive. ai
semgrep semgrep:child-process-execsync AI (semgrep): musl detection via 'which ldd' for native binary selection, not arbitrary exec. ai
semgrep semgrep:dynamic-require AI (semgrep): Requires standard 'v8' module conditionally; not arbitrary module loading. ai
typosquat typosquat.levenshtein:ajv AI (typosquat): False positive; unrelated package. ai

Versions (showing 10 of 10)

Version Deps Published
0.14.0 0 / 0
0.13.0 0 / 0
0.12.0 0 / 0
0.10.0 0 / 0
0.9.0 0 / 0
0.8.4 0 / 0
0.8.3 0 / 0
0.8.2 0 / 0
0.8.1 0 / 0
0.8.0 0 / 0

v0.10.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.9.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.