← Home

@fedify/init

57
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

hongminheez9mb12chanhaeng

Keywords

fedifyactivitypubcliinit

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern rapid-publish AI (publish-pattern): Published via GitHub Actions CI/CD with SLSA provenance; rapid successive publishes are expected for this automated pipeline. ai
publish-pattern new-deps-added AI (publish-pattern): @david/dax is an alias for the well-known dax shell utility; addition is consistent with CLI tooling use case. ai
dependencies unvetted-dep:@david/dax AI (dependencies): dax is a well-known cross-runtime shell utility; aliased as @david/dax, no malicious history. ai
dependencies unvetted-dep:@logtape/logtape AI (dependencies): @logtape/logtape is a structured logging library; its use here is standard and low-risk for a CLI initializer. ai
dependencies unvetted-dep:@fxts/core AI (dependencies): @fxts/core is a well-known functional programming utility library for JS/TS; its use in a CLI initializer tool is appropriate and low-risk. ai
dependencies unvetted-dep:inquirer-toggle AI (dependencies): inquirer-toggle is a standard interactive prompt plugin for the Inquirer.js ecosystem; appropriate for a CLI tool. ai
provenance slsa-provenance AI (provenance): Package consistently published via CI/CD with Sigstore SLSA attestation; this is a stable property of the fedify-dev/fedify monorepo release pipeline. ai

Versions (showing 57 of 57)

Version Deps Published
2.3.3 10 / 3
2.3.2 10 / 3
2.3.1 10 / 3
2.3.0 10 / 3
2.2.8 9 / 3
2.2.7 9 / 3
2.2.6 9 / 3
2.2.5 9 / 3
2.2.4 9 / 3
2.2.3 9 / 3
2.2.2 9 / 3
2.2.1 9 / 3
2.2.0 9 / 3
2.1.19 8 / 3
2.1.18 8 / 3
2.1.17 8 / 3
2.1.16 8 / 3
2.1.15 8 / 3
2.1.14 8 / 3
2.1.13 8 / 3
2.1.12 8 / 3
2.1.11 8 / 3
2.1.10 8 / 3
2.1.9 8 / 3
2.1.8 8 / 3
2.1.7 8 / 3
2.1.6 8 / 3
2.1.5 8 / 3
2.1.4 8 / 3
2.1.3 8 / 3
2.1.2 8 / 3
2.1.1 8 / 3
2.1.0 8 / 3
2.0.23 8 / 3
2.0.22 8 / 3
2.0.21 8 / 3
2.0.20 8 / 3
2.0.19 8 / 3
2.0.18 8 / 3
2.0.17 8 / 3
2.0.16 8 / 3
2.0.15 8 / 3
2.0.14 8 / 3
2.0.13 8 / 3
2.0.12 8 / 3
2.0.11 8 / 3
2.0.10 8 / 3
2.0.9 8 / 3
2.0.8 8 / 3
2.0.7 8 / 3
2.0.6 8 / 3
2.0.5 8 / 3
2.0.4 8 / 3
2.0.3 8 / 3
2.0.2 8 / 3
2.0.1 8 / 3
2.0.0 8 / 3

v2.3.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.19

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.18

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.17

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.23

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.22

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.21

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.