@effect/platform-node-shared
Unified interfaces for common platform-specific services
51
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
schicklingmichael.arnaldieffect-bot
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Effect-TS migrated from personal npm publishing (michael.arnaldi) to GitHub Actions CI/CD with SLSA provenance attestation — a security improvement, not a compromise signal. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Package has 471 versions and is actively maintained; the dormancy gap is a registry artifact, not indicative of account takeover. SLSA provenance further confirms legitimate CI publishing. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): Spreading process.env into child_process options is the standard pattern for a command executor passing environment to subprocesses. No exfiltration; stable false positive for this package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Part of the well-established Effect-TS monorepo with 471 versions. Short README and missing keywords are cosmetic; not a spam or low-value package. | ai |
Versions (showing 51 of 385)
| Version | Deps | Published |
|---|---|---|
| 0.61.0 | 3 / 0 | |
| 0.60.0 | 3 / 0 | |
| 0.59.0 | 3 / 0 | |
| 0.58.0 | 3 / 0 | |
| 0.57.1 | 3 / 0 | |
| 0.57.0 | 3 / 0 | |
| 0.56.0 | 3 / 0 | |
| 0.55.0 | 3 / 0 | |
| 0.54.0 | 3 / 0 | |
| 0.53.0 | 3 / 0 | |
| 0.52.0 | 3 / 0 | |
| 0.51.6 | 3 / 0 | |
| 0.51.5 | 3 / 0 | |
| 0.51.4 | 3 / 0 | |
| 0.51.3 | 3 / 0 | |
| 0.51.2 | 3 / 0 | |
| 0.51.1 | 3 / 0 | |
| 0.51.0 | 3 / 0 | |
| 0.50.1 | 3 / 0 | |
| 0.50.0 | 3 / 0 | |
| 0.49.2 | 3 / 0 | |
| 0.49.1 | 3 / 0 | |
| 0.49.0 | 3 / 0 | |
| 0.48.1 | 3 / 0 | |
| 0.48.0 | 3 / 0 | |
| 0.47.2 | 3 / 0 | |
| 0.47.1 | 3 / 0 | |
| 0.47.0 | 3 / 0 | |
| 0.46.0 | 3 / 0 | |
| 0.45.0 | 3 / 0 | |
| 0.44.0 | 3 / 0 | |
| 0.43.0 | 3 / 0 | |
| 0.42.18 | 3 / 0 | |
| 0.42.17 | 3 / 0 | |
| 0.42.15 | 3 / 0 | |
| 0.42.14 | 3 / 0 | |
| 0.42.13 | 3 / 0 | |
| 0.42.12 | 3 / 0 | |
| 0.42.11 | 3 / 0 | |
| 0.42.10 | 3 / 0 | |
| 0.42.9 | 3 / 0 | |
| 0.42.8 | 3 / 0 | |
| 0.42.7 | 3 / 0 | |
| 0.42.6 | 3 / 0 | |
| 0.42.5 | 3 / 0 | |
| 0.42.4 | 3 / 0 | |
| 0.42.3 | 3 / 0 | |
| 0.42.2 | 3 / 0 | |
| 0.42.1 | 3 / 0 | |
| 0.42.0 | 3 / 0 | |
| 0.41.0 | 3 / 0 |
v0.61.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.