← Home

@feasibleone/blong

49
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

kalin.krustev

Keywords

blongradframework

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): SLSA provenance attestation present; gitHead absence is superseded by Sigstore attestation for this package. ai
phantom-deps phantom-dep:openapi-types AI (phantom-deps): openapi-types is declared in both deps and devDeps; likely used for type re-exports rather than direct imports. ai
publish-pattern new-deps-added AI (publish-pattern): typebox is a rename/repackage of @sinclair/typebox which was already a dependency; not a novel third-party dep. ai
npm-metadata url-dep:@types/ut-function.merge AI (npm-metadata): Local file: path for a devDependency type stub; no runtime risk, stable pattern for this package. ai
phantom-deps phantom-dep:ut-function.merge AI (phantom-deps): Config-file reference; stable pattern for this package. ai
phantom-deps phantom-dep:@sinclair/typebox AI (phantom-deps): Config-file reference; stable pattern for this package. ai
phantom-deps phantom-dep:pino AI (phantom-deps): Config-file reference; stable pattern for this package. ai
dependencies unvetted-dep:ut-function.merge AI (dependencies): Stable utility dep used across many versions of this package; no known advisories. ai

Versions (showing 49 of 49)

Version Deps Published
1.23.0 4 / 22
1.22.0 4 / 22
1.21.0 4 / 22
1.20.1 4 / 22
1.20.0 4 / 22
1.19.0 4 / 21
1.18.3 4 / 21
1.18.2 4 / 21
1.18.1 4 / 21
1.18.0 4 / 19
1.17.0 4 / 19
1.16.1 4 / 20
1.16.0 4 / 20
1.15.0 4 / 20
1.14.0 4 / 20
1.13.0 4 / 20
1.12.4 4 / 20
1.12.3 4 / 20
1.12.2 4 / 20
1.12.1 4 / 20
1.12.0 4 / 20
1.11.0 4 / 20
1.10.1 4 / 20
1.10.0 4 / 20
1.9.6 4 / 20
1.9.5 4 / 20
1.9.4 4 / 20
1.9.3 4 / 20
1.9.2 4 / 20
1.9.1 4 / 20
1.9.0 4 / 20
1.8.0 4 / 19
1.7.3 4 / 19
1.7.2 4 / 19
1.7.1 4 / 19
1.7.0 4 / 19
1.6.0 4 / 19
1.5.2 4 / 19
1.5.1 4 / 19
1.5.0 4 / 19
1.4.0 4 / 19
1.3.0 4 / 18
1.2.0 3 / 7
1.1.0 3 / 7
1.0.7 3 / 7
1.0.6 3 / 7
1.0.5 3 / 7
1.0.4 3 / 7
0.0.1 3 / 7

v1.23.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.