@ghostery/trackerdb
Ghostery Tracker Database
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:enolib | AI (dependencies): Small ENO parsing library; no known advisories; stable dependency for this package. | ai | |
| dependencies | unvetted-dep:iso-3166-1-alpha-2 | AI (dependencies): Tiny country-code lookup library; no known advisories; stable dependency for this package. | ai | |
| phantom-deps | phantom-dep:enolib | AI (phantom-deps): Used in build/export scripts for ENO config parsing; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:iso-3166-1-alpha-2 | AI (phantom-deps): Country code lookup utility used in build scripts; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:tldts-experimental | AI (phantom-deps): TLD resolution used in tracker DB processing; stable false positive for this package. | ai |
Versions (showing 35 of 235)
| Version | Deps | Published |
|---|---|---|
| 1.0.715 | 4 / 15 | |
| 1.0.714 | 4 / 15 | |
| 1.0.713 | 4 / 15 | |
| 1.0.712 | 4 / 15 | |
| 1.0.711 | 4 / 15 | |
| 1.0.710 | 4 / 15 | |
| 1.0.709 | 4 / 15 | |
| 1.0.708 | 4 / 15 | |
| 1.0.707 | 4 / 15 | |
| 1.0.706 | 4 / 15 | |
| 1.0.692 | 4 / 15 | |
| 1.0.691 | 4 / 15 | |
| 1.0.690 | 4 / 15 | |
| 1.0.689 | 4 / 15 | |
| 1.0.688 | 4 / 15 | |
| 1.0.687 | 4 / 15 | |
| 1.0.686 | 4 / 15 | |
| 1.0.685 | 4 / 15 | |
| 1.0.684 | 4 / 15 | |
| 1.0.683 | 4 / 15 | |
| 1.0.682 | 4 / 15 | |
| 1.0.681 | 4 / 15 | |
| 1.0.680 | 4 / 15 | |
| 1.0.679 | 4 / 15 | |
| 1.0.678 | 4 / 15 | |
| 1.0.677 | 4 / 15 | |
| 1.0.676 | 4 / 15 | |
| 1.0.675 | 4 / 15 | |
| 1.0.674 | 4 / 15 | |
| 1.0.673 | 4 / 15 | |
| 1.0.672 | 4 / 15 | |
| 1.0.671 | 4 / 15 | |
| 1.0.670 | 4 / 15 | |
| 1.0.669 | 4 / 15 | |
| 1.0.668 | 4 / 15 |
v1.0.715
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.714
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.713
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.712
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.711
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.710
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.709
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.708
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.707
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.706
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.692
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.691
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.690
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.689
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.688
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.687
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.686
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.685
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.684
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.683
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.682
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.681
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.680
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.679
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.678
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.677
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.676
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.675
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.674
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.673
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.672
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.671
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.670
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.669
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.668
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.