@expofp/offline
CLI tool for creating offline copies of ExpoFP floor plans
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-added | AI (maintainer-change): Routine team addition; provenance and content unchanged vs prior approved version. | ai | |
| dependencies | unvetted-dep:@expofp/schema | AI (dependencies): First-party sibling package in same monorepo, version-locked to release. | ai | |
| dependencies | unvetted-dep:@expofp/config | AI (dependencies): First-party sibling package in same monorepo, version-locked to release. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): CI/CD-published package, no material code change; consistent with maintainer consolidation not takeover. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): Monorepo with synchronized versioning; rapid publishes are expected across @expofp/* packages. | ai | |
| dependencies | unvetted-dep:@expofp/floorplan | AI (dependencies): First-party sibling dep pinned to same version; consistent with monorepo release pattern. | ai | |
| dependencies | unvetted-dep:@expofp/geometry | AI (dependencies): First-party sibling dep pinned to same version; consistent with monorepo release pattern. | ai | |
| provenance | no-provenance | AI (provenance): Published via GitHub Actions CI; provenance attestation not yet enabled but no other risk signals present. | ai | |
| phantom-deps | phantom-dep:tslib | AI (phantom-deps): tslib is a known implicit TypeScript runtime dep; stable false positive for this package. | ai |
Versions (showing 60 of 60)
| Version | Deps | Published |
|---|---|---|
| 3.12.0 | 8 / 0 | |
| 3.11.12 | 7 / 0 | |
| 3.11.10 | 7 / 0 | |
| 3.11.9 | 7 / 0 | |
| 3.11.8 | 7 / 0 | |
| 3.11.7 | 7 / 0 | |
| 3.11.5 | 7 / 0 | |
| 3.11.4 | 7 / 0 | |
| 3.11.2 | 7 / 0 | |
| 3.11.0 | 7 / 0 | |
| 3.10.2 | 7 / 0 | |
| 3.10.1 | 7 / 0 | |
| 3.10.0 | 7 / 0 | |
| 3.9.0 | 7 / 0 | |
| 3.8.0 | 7 / 0 | |
| 3.7.17 | 6 / 0 | |
| 3.7.16 | 6 / 0 | |
| 3.7.15 | 6 / 0 | |
| 3.7.14 | 6 / 0 | |
| 3.7.13 | 6 / 0 | |
| 3.7.12 | 6 / 0 | |
| 3.7.11 | 6 / 0 | |
| 3.7.8 | 6 / 0 | |
| 3.7.5 | 6 / 0 | |
| 3.6.7 | 6 / 0 | |
| 3.6.4 | 6 / 0 | |
| 3.6.1 | 6 / 0 | |
| 3.6.0 | 6 / 0 | |
| 3.4.1 | 6 / 0 | |
| 3.4.0 | 6 / 0 | |
| 3.3.3 | 6 / 0 | |
| 3.3.2 | 6 / 0 | |
| 3.3.1 | 6 / 0 | |
| 3.2.16 | 6 / 0 | |
| 3.2.15 | 6 / 0 | |
| 3.2.14 | 6 / 0 | |
| 3.2.13 | 6 / 0 | |
| 3.2.12 | 6 / 0 | |
| 3.2.7 | 6 / 0 | |
| 3.2.5 | 6 / 0 | |
| 3.2.4 | 6 / 0 | |
| 3.2.3 | 6 / 0 | |
| 3.2.1 | 6 / 0 | |
| 3.2.0 | 6 / 0 | |
| 3.1.16 | 6 / 0 | |
| 3.1.15 | 6 / 0 | |
| 3.1.13 | 6 / 0 | |
| 3.1.11 | 6 / 0 | |
| 3.1.10 | 6 / 0 | |
| 3.1.9 | 6 / 0 | |
| 3.1.8 | 6 / 0 | |
| 3.1.6 | 6 / 0 | |
| 3.1.5 | 6 / 0 | |
| 3.1.4 | 6 / 0 | |
| 3.1.3 | 6 / 0 | |
| 3.1.2 | 6 / 0 | |
| 3.1.0 | 6 / 0 | |
| 3.0.2 | 6 / 0 | |
| 3.0.1 | 6 / 0 | |
| 3.0.0 | 6 / 0 |
v3.12.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.11.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.11.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.11.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.11.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.11.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.11.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.11.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.11.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.11.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.