← Home

@dxos/plugin-pwa

DXOS Surface plugin for PWA registration and update handling.

16
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

richburdonmarik_dwittjosiahdxos-botmykola-vrmchk

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): dxos-bot → GitHub Actions is a CI pipeline migration within the same dxos org; SLSA attestation confirms legitimate automated publish. ai
maintainer-change maintainer-removed AI (maintainer-change): Maintainer removal consistent with org-level CI migration; monorepo publishing moved to GitHub Actions. ai
dependencies unvetted-dep:@dxos/app-toolkit AI (dependencies): First-party @dxos monorepo package at matching version 0.9.0; not a third-party supply chain risk. ai
bogus-package bogus-package AI (bogus-package): Monorepo sub-package; minimal README is expected, not indicative of spam or phishing. ai

Versions (showing 16 of 16)

Version Deps Published
0.9.0 6 / 11
0.8.3 5 / 11
0.8.2 5 / 11
0.8.1 3 / 11
0.8.0 3 / 11
0.7.4 3 / 11
0.7.3 3 / 11
0.7.2 3 / 11
0.7.1 3 / 11
0.7.0 3 / 11
0.6.13 5 / 9
0.6.12 5 / 9
0.6.11 5 / 9
0.6.10 5 / 9
0.6.9 5 / 9
0.6.8 5 / 9

v0.8.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.8.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.6.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.