← Home

@fastify/cors

2
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

simonebdelvedormatteo.collinajsumnerszektheommfox1tairhornskibertoadclimba03003galvezsimenbgurgundaymetcoder95jean-micheletilteooodfdawgs

Keywords

fastifycorsheadersaccesscontrol

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:fastify-plugin AI (dependencies): fastify-plugin is a core Fastify ecosystem utility; its use in @fastify/cors is expected and stable across all versions. ai
dependencies unvetted-dep:toad-cache AI (dependencies): toad-cache is a standard LRU/TTL cache used throughout the Fastify plugin ecosystem; its use here is expected and legitimate. ai
provenance no-provenance AI (provenance): Lack of Sigstore provenance is common (~88% of npm packages); not a meaningful risk signal for this well-established Fastify org package. ai

Versions (showing 2 of 2)

Version Deps Published
11.2.0 2 / 8
11.1.0 2 / 9

v11.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v11.1.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.