@duckcodeailabs/dql-lsp
DQL Language Server Protocol implementation
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): Metadata-only signal; no behavioral change, publisher has strong track record. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): Rapid publish alone with no diff is benign for this monorepo-style package. | ai | |
| provenance | no-provenance | AI (provenance): Absence of Sigstore provenance is common (~88% of packages lack it) and is not a risk indicator for this package given clean metadata and no other suspicious signals. | ai |
Versions (showing 26 of 127)
| Version | Deps | Published |
|---|---|---|
| 0.8.14 | 3 / 1 | |
| 0.8.13 | 3 / 1 | |
| 0.8.12 | 3 / 1 | |
| 0.8.11 | 3 / 1 | |
| 0.8.10 | 3 / 1 | |
| 0.8.9 | 3 / 1 | |
| 0.8.8 | 3 / 1 | |
| 0.8.7 | 3 / 1 | |
| 0.8.6 | 3 / 1 | |
| 0.8.5 | 3 / 1 | |
| 0.8.4 | 3 / 1 | |
| 0.8.3 | 3 / 1 | |
| 0.8.2 | 3 / 1 | |
| 0.8.1 | 3 / 1 | |
| 0.8.0 | 3 / 1 | |
| 0.7.1 | 3 / 1 | |
| 0.7.0 | 3 / 1 | |
| 0.6.0 | 3 / 1 | |
| 0.1.7 | 3 / 1 | |
| 0.1.6 | 3 / 1 | |
| 0.1.5 | 3 / 1 | |
| 0.1.4 | 3 / 1 | |
| 0.1.3 | 3 / 1 | |
| 0.1.2 | 3 / 1 | |
| 0.1.1 | 3 / 1 | |
| 0.1.0 | 3 / 1 |
v0.8.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.