@feasibleone/blong
49
Versions
—
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
kalin.krustev
Keywords
blongradframework
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): SLSA provenance attestation present; gitHead absence is superseded by Sigstore attestation for this package. | ai | |
| phantom-deps | phantom-dep:openapi-types | AI (phantom-deps): openapi-types is declared in both deps and devDeps; likely used for type re-exports rather than direct imports. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): typebox is a rename/repackage of @sinclair/typebox which was already a dependency; not a novel third-party dep. | ai | |
| npm-metadata | url-dep:@types/ut-function.merge | AI (npm-metadata): Local file: path for a devDependency type stub; no runtime risk, stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:ut-function.merge | AI (phantom-deps): Config-file reference; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@sinclair/typebox | AI (phantom-deps): Config-file reference; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:pino | AI (phantom-deps): Config-file reference; stable pattern for this package. | ai | |
| dependencies | unvetted-dep:ut-function.merge | AI (dependencies): Stable utility dep used across many versions of this package; no known advisories. | ai |
Versions (showing 49 of 49)
| Version | Deps | Published |
|---|---|---|
| 1.23.0 | 4 / 22 | |
| 1.22.0 | 4 / 22 | |
| 1.21.0 | 4 / 22 | |
| 1.20.1 | 4 / 22 | |
| 1.20.0 | 4 / 22 | |
| 1.19.0 | 4 / 21 | |
| 1.18.3 | 4 / 21 | |
| 1.18.2 | 4 / 21 | |
| 1.18.1 | 4 / 21 | |
| 1.18.0 | 4 / 19 | |
| 1.17.0 | 4 / 19 | |
| 1.16.1 | 4 / 20 | |
| 1.16.0 | 4 / 20 | |
| 1.15.0 | 4 / 20 | |
| 1.14.0 | 4 / 20 | |
| 1.13.0 | 4 / 20 | |
| 1.12.4 | 4 / 20 | |
| 1.12.3 | 4 / 20 | |
| 1.12.2 | 4 / 20 | |
| 1.12.1 | 4 / 20 | |
| 1.12.0 | 4 / 20 | |
| 1.11.0 | 4 / 20 | |
| 1.10.1 | 4 / 20 | |
| 1.10.0 | 4 / 20 | |
| 1.9.6 | 4 / 20 | |
| 1.9.5 | 4 / 20 | |
| 1.9.4 | 4 / 20 | |
| 1.9.3 | 4 / 20 | |
| 1.9.2 | 4 / 20 | |
| 1.9.1 | 4 / 20 | |
| 1.9.0 | 4 / 20 | |
| 1.8.0 | 4 / 19 | |
| 1.7.3 | 4 / 19 | |
| 1.7.2 | 4 / 19 | |
| 1.7.1 | 4 / 19 | |
| 1.7.0 | 4 / 19 | |
| 1.6.0 | 4 / 19 | |
| 1.5.2 | 4 / 19 | |
| 1.5.1 | 4 / 19 | |
| 1.5.0 | 4 / 19 | |
| 1.4.0 | 4 / 19 | |
| 1.3.0 | 4 / 18 | |
| 1.2.0 | 3 / 7 | |
| 1.1.0 | 3 / 7 | |
| 1.0.7 | 3 / 7 | |
| 1.0.6 | 3 / 7 | |
| 1.0.5 | 3 / 7 | |
| 1.0.4 | 3 / 7 | |
| 0.0.1 | 3 / 7 |
v1.23.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.