← Home

@duckcodeailabs/dql-compiler

DQL compiler: IR lowering, Vega-Lite code generation, HTML/CSS emitting

30
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

duckcode

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): Frequent monorepo publisher; no diff vs prior approved version, no behavioral change. ai
publish-pattern rapid-publish AI (publish-pattern): Consistent with automated monorepo release cadence across 112 versions. ai
provenance no-provenance AI (provenance): Provenance absence is common (~88% of npm packages lack it); no other risk signals present to elevate this finding for this package. ai

Versions (showing 30 of 130)

Version Deps Published
0.8.16 1 / 3
0.8.15 1 / 3
0.8.14 1 / 3
0.8.13 1 / 3
0.8.12 1 / 3
0.8.11 1 / 3
0.8.10 1 / 3
0.8.9 1 / 3
0.8.8 1 / 3
0.8.7 1 / 3
0.8.6 1 / 3
0.8.5 1 / 3
0.8.4 1 / 3
0.8.3 1 / 3
0.8.2 1 / 3
0.8.1 1 / 3
0.8.0 1 / 3
0.7.1 1 / 3
0.7.0 1 / 3
0.6.0 1 / 3
0.2.3 1 / 3
0.2.2 1 / 3
0.2.1 1 / 3
0.2.0 1 / 3
0.1.5 1 / 3
0.1.4 1 / 3
0.1.3 1 / 3
0.1.2 1 / 3
0.1.1 1 / 3
0.1.0 1 / 3

v0.8.8

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.8.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.8.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.8.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.