← Home

@fluojs/di

Minimal token-based dependency injection container powering every Fluo application.

5
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

ayden94

Keywords

fluodidependency-injectionioccontainerprovider

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
typosquat typosquat.levenshtein:pg AI (typosquat): Scoped @fluojs/di is a DI container, not a typosquat of pg; edit-distance match is coincidental. ai
typosquat typosquat.levenshtein:qs AI (typosquat): Scoped @fluojs/di is a DI container, not a typosquat of qs; edit-distance match is coincidental. ai
typosquat typosquat.levenshtein:joi AI (typosquat): Scoped @fluojs/di is a DI container, not a typosquat of joi; edit-distance match is coincidental. ai
dependencies unvetted-dep:@fluojs/core AI (dependencies): Sibling package in the same fluojs monorepo; expected internal dependency. ai

Versions (showing 5 of 5)

Version Deps Published
1.1.0 1 / 1
1.0.3 1 / 1
1.0.2 1 / 1
1.0.1 1 / 1
1.0.0 1 / 1

v1.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.