← Home

@gcornut/valibot-json-schema

1
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

gcornut

Keywords

valibotschemaclijson-schema

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:child-process-import AI (semgrep): CLI binary bundles Commander.js which uses child_process for sub-command spawning; expected pattern for this CLI tool. ai
semgrep semgrep:child-process-spawn AI (semgrep): Spawns process.argv[0] or a resolved executable for CLI sub-commands; standard Commander.js pattern, not arbitrary code execution. ai
semgrep semgrep:dynamic-require AI (semgrep): Loads user-supplied schema source file via CLI argument; intentional and documented CLI behavior. ai

Versions (showing 1 of 1)

Version Deps Published
0.42.0 1 / 16

v0.42.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.