← Home

@frontmcp/di

34
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

davidfrontegg

Keywords

dependency-injectiondiioccontainerregistrytypescriptdecoratorsreflect-metadatainversion-of-control

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI publishing is confirmed legitimate by SLSA/Sigstore provenance attestation. ai
provenance slsa-provenance AI (provenance): Package consistently published with SLSA provenance; stable signal for this package. ai
typosquat typosquat.levenshtein:pg AI (typosquat): Scoped DI library; Levenshtein match on short name 'pg' is a false positive. ai
typosquat typosquat.levenshtein:qs AI (typosquat): Scoped DI library; Levenshtein match on short name 'qs' is a false positive. ai
typosquat typosquat.levenshtein:joi AI (typosquat): Scoped DI library; Levenshtein match on short name 'joi' is a false positive. ai
phantom-deps phantom-dep:mitt AI (phantom-deps): mitt is a declared runtime dependency; phantom-dep heuristic misfired on import style. ai

Versions (showing 34 of 34)

Version Deps Published
1.5.6 0 / 4
1.5.5 0 / 4
1.5.4 0 / 4
1.5.3 0 / 4
1.5.2 0 / 4
1.5.1 0 / 4
1.5.0 0 / 4
1.4.1 1 / 4
1.4.0 1 / 4
1.3.0 1 / 4
1.2.1 1 / 4
1.2.0 1 / 4
1.1.2 1 / 4
1.1.1 1 / 4
1.1.0 1 / 4
1.0.4 1 / 4
1.0.3 1 / 4
1.0.2 1 / 4
1.0.1 1 / 4
1.0.0 1 / 4
0.12.2 1 / 4
0.12.1 1 / 4
0.12.0 1 / 4
0.11.3 1 / 4
0.11.2 1 / 4
0.11.1 1 / 4
0.11.0 1 / 4
0.10.0 1 / 4
0.9.0 1 / 4
0.8.1 1 / 4
0.8.0 1 / 4
0.7.2 1 / 4
0.7.1 1 / 4
0.0.1 1 / 4

v1.5.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.5.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.5.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.5.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.