← Home

@dxos/plugin-settings

DXOS app plugin for aggregating and rendering plugin settings.

7
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

richburdonmarik_dwittjosiahdxos-botmykola-vrmchk

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): dxos-bot → GitHub Actions is an org-internal CI account transition, backed by SLSA provenance attestation. ai
dependencies unvetted-dep:@dxos/app-toolkit AI (dependencies): First-party @dxos scoped dep at matching monorepo version; not a third-party injection. ai
dependencies unvetted-dep:@dxos/app-framework AI (dependencies): First-party @dxos scoped dep at matching monorepo version; not a third-party injection. ai
bogus-package bogus-package AI (bogus-package): DXOS monorepo component; minimal README is standard for internal packages, not spam. ai

Versions (showing 7 of 7)

Version Deps Published
0.9.0 7 / 4
0.6.13 5 / 7
0.6.12 5 / 7
0.6.11 5 / 7
0.6.10 5 / 7
0.6.9 5 / 7
0.6.8 5 / 7

v0.6.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.