@dxos/plugin-pwa
DXOS Surface plugin for PWA registration and update handling.
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): dxos-bot → GitHub Actions is a CI pipeline migration within the same dxos org; SLSA attestation confirms legitimate automated publish. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Maintainer removal consistent with org-level CI migration; monorepo publishing moved to GitHub Actions. | ai | |
| dependencies | unvetted-dep:@dxos/app-toolkit | AI (dependencies): First-party @dxos monorepo package at matching version 0.9.0; not a third-party supply chain risk. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Monorepo sub-package; minimal README is expected, not indicative of spam or phishing. | ai |
Versions (showing 16 of 16)
| Version | Deps | Published |
|---|---|---|
| 0.9.0 | 6 / 11 | |
| 0.8.3 | 5 / 11 | |
| 0.8.2 | 5 / 11 | |
| 0.8.1 | 3 / 11 | |
| 0.8.0 | 3 / 11 | |
| 0.7.4 | 3 / 11 | |
| 0.7.3 | 3 / 11 | |
| 0.7.2 | 3 / 11 | |
| 0.7.1 | 3 / 11 | |
| 0.7.0 | 3 / 11 | |
| 0.6.13 | 5 / 9 | |
| 0.6.12 | 5 / 9 | |
| 0.6.11 | 5 / 9 | |
| 0.6.10 | 5 / 9 | |
| 0.6.9 | 5 / 9 | |
| 0.6.8 | 5 / 9 |
v0.8.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.