← Home

@fairmint/canton-node-sdk

6
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

thibauldnickcusoleekt216adamhursey_workollitylershubhjkenny_fairmint

Keywords

cantonsdktypescriptblockchaindaml

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:glob AI (phantom-deps): Build-time tool used in scripts; correctly declared as runtime dep. ai
phantom-deps phantom-dep:openapi-typescript AI (phantom-deps): Build-time code generator; correctly declared as runtime dep. ai
phantom-deps phantom-dep:openapi-fetch AI (phantom-deps): Build-time tool used in scripts; correctly declared as runtime dep. ai

Versions (showing 6 of 106)

Version Deps Published
0.0.34 5 / 16
0.0.33 5 / 16
0.0.32 5 / 16
0.0.31 5 / 16
0.0.30 5 / 16
0.0.29 5 / 16

v0.0.34

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.33

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.32

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.31

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.30

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.29

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.