@dxos/plugin-settings
DXOS app plugin for aggregating and rendering plugin settings.
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): dxos-bot → GitHub Actions is an org-internal CI account transition, backed by SLSA provenance attestation. | ai | |
| dependencies | unvetted-dep:@dxos/app-toolkit | AI (dependencies): First-party @dxos scoped dep at matching monorepo version; not a third-party injection. | ai | |
| dependencies | unvetted-dep:@dxos/app-framework | AI (dependencies): First-party @dxos scoped dep at matching monorepo version; not a third-party injection. | ai | |
| bogus-package | bogus-package | AI (bogus-package): DXOS monorepo component; minimal README is standard for internal packages, not spam. | ai |
Versions (showing 7 of 7)
| Version | Deps | Published |
|---|---|---|
| 0.9.0 | 7 / 4 | |
| 0.6.13 | 5 / 7 | |
| 0.6.12 | 5 / 7 | |
| 0.6.11 | 5 / 7 | |
| 0.6.10 | 5 / 7 | |
| 0.6.9 | 5 / 7 | |
| 0.6.8 | 5 / 7 |
v0.6.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.