← Home

@directus/env

Utilities around using global env configuration

26
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

benhaynesrijkalexgaillard88

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Directus migrated to GitHub Actions publishing with SLSA attestation; transition from personal account is expected. ai
publish-pattern dormant-publish AI (publish-pattern): Dormancy reflects monorepo release cadence, not account takeover; SLSA attestation confirms CI/CD origin. ai
dependencies unvetted-dep:@directus/constants AI (dependencies): Sibling package within the directus monorepo; same publisher and trust chain. ai
typosquat typosquat.levenshtein:ajv AI (typosquat): Scoped @directus/* package from the official Directus monorepo; no relation to ajv. ai
bogus-package bogus-package AI (bogus-package): Internal monorepo utility package; sparse README and no keywords are expected for internal packages. ai

Versions (showing 26 of 26)

Version Deps Published
6.1.0 4 / 7
6.0.0 4 / 7
5.8.0 4 / 7
5.7.1 4 / 7
5.7.0 4 / 7
5.6.1 4 / 7
5.6.0 4 / 7
5.5.3 4 / 7
5.5.2 4 / 7
5.5.1 4 / 7
5.5.0 4 / 7
5.4.0 4 / 7
5.3.3 4 / 7
5.3.2 4 / 7
5.3.1 4 / 7
5.3.0 4 / 7
5.2.0 4 / 7
5.1.2 4 / 7
5.1.1 4 / 7
5.1.0 4 / 7
5.0.5 4 / 7
5.0.4 4 / 7
5.0.3 4 / 7
5.0.2 4 / 7
5.0.1 4 / 7
5.0.0 4 / 7

v6.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.0.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.0.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.0.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.