@docmd/plugin-threads
Inline discussion threads for docmd documentation sites.
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions publisher is confirmed by SLSA provenance attestation; consistent with CI/CD automation. | ai | |
| phantom-deps | phantom-dep:lit | AI (phantom-deps): lit is a declared runtime dep used in a bundled plugin; not directly imported at source level is expected. | ai | |
| phantom-deps | phantom-dep:@awesome.me/webawesome | AI (phantom-deps): Declared runtime dep referenced in build config; phantom-dep heuristic is a false positive for bundled packages. | ai |
Versions (showing 30 of 30)
| Version | Deps | Published |
|---|---|---|
| 0.8.16 | 3 / 4 | |
| 0.8.15 | 3 / 4 | |
| 0.8.14 | 3 / 4 | |
| 0.8.13 | 3 / 4 | |
| 0.8.12 | 3 / 4 | |
| 0.8.11 | 3 / 4 | |
| 0.8.10 | 2 / 4 | |
| 0.8.9 | 2 / 4 | |
| 0.8.8 | 2 / 4 | |
| 0.8.7 | 2 / 4 | |
| 0.8.6 | 2 / 4 | |
| 0.8.5 | 2 / 4 | |
| 0.8.4 | 2 / 4 | |
| 0.8.3 | 2 / 4 | |
| 0.8.2 | 2 / 4 | |
| 0.8.1 | 2 / 4 | |
| 0.8.0 | 2 / 5 | |
| 0.7.9 | 2 / 5 | |
| 0.7.8 | 2 / 5 | |
| 0.7.7 | 2 / 5 | |
| 0.7.6 | 2 / 5 | |
| 0.7.5 | 2 / 5 | |
| 0.7.4 | 2 / 5 | |
| 0.7.3 | 2 / 5 | |
| 0.7.2 | 2 / 5 | |
| 0.7.1 | 2 / 5 | |
| 0.7.0 | 2 / 4 | |
| 0.6.9 | 2 / 4 | |
| 0.6.8 | 2 / 4 | |
| 0.6.7 | 2 / 4 |
v0.8.16
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.15
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.14
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.13
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.