← Home

@galacean/engine-shaderlab

```sh npm install @galacean/engine-shaderlab ```

7
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

yiqiimchenjianchengkong.zxxeyworldwideyinjieruimeng.sugl3336563zhanyingweizhuxudongjohanzhumrkou47husongluzhuangjujiefeyabibi

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
email-domain unclaimed-email:yufangjun.com AI (email-domain): SLSA provenance attestation via Sigstore provides strong supply chain integrity, offsetting the unclaimed domain risk for this established package. ai

Versions (showing 7 of 7)

Version Deps Published
1.6.13 0 / 2
1.6.12 0 / 2
1.6.11 0 / 2
1.6.10 0 / 2
1.6.9 0 / 2
1.6.8 0 / 2
1.5.16 0 / 2

v1.6.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.6.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.6.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.6.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.5.16

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.