@goldstack/template-hetzner-vps
Utilities for packages that help provision Hetzner Servers
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@goldstack/infra | AI (dependencies): Same-org monorepo dependency; not an independent supply-chain risk. | ai | |
| dependencies | unvetted-dep:@goldstack/infra-aws | AI (dependencies): Same-org monorepo dependency; not an independent supply-chain risk. | ai | |
| dependencies | unvetted-dep:@goldstack/utils-cli | AI (dependencies): Same-org monorepo dependency; not an independent supply-chain risk. | ai | |
| dependencies | unvetted-dep:@goldstack/infra-hetzner | AI (dependencies): Same-org monorepo dependency; not an independent supply-chain risk. | ai | |
| dependencies | unvetted-dep:@goldstack/utils-esbuild | AI (dependencies): Same-org monorepo dependency; not an independent supply-chain risk. | ai | |
| dependencies | unvetted-dep:@goldstack/utils-package | AI (dependencies): Same-org monorepo dependency; not an independent supply-chain risk. | ai | |
| dependencies | unvetted-dep:@goldstack/utils-package-config-embedded | AI (dependencies): Same-org monorepo dependency; not an independent supply-chain risk. | ai | |
| phantom-deps | phantom-dep:uuid | AI (phantom-deps): Declared in dependencies; likely used transitively or in config — stable false positive for this package. | ai | |
| provenance | no-provenance | AI (provenance): Established monorepo package; lack of provenance is common and not a disqualifier here. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/types | AI (phantom-deps): Framework-scoped AWS SDK type package; loaded by convention, not direct import. | ai | |
| phantom-deps | phantom-dep:@goldstack/utils-cli | AI (phantom-deps): Same-org monorepo dep; phantom detection is a stable false positive here. | ai | |
| phantom-deps | phantom-dep:@goldstack/utils-esbuild | AI (phantom-deps): Same-org monorepo dep; phantom detection is a stable false positive here. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/credential-providers | AI (phantom-deps): Framework-scoped AWS SDK package; loaded by convention, not direct import. | ai | |
| phantom-deps | phantom-dep:@goldstack/utils-terraform-aws | AI (phantom-deps): Same-org monorepo dep; phantom detection is a stable false positive here. | ai | |
| phantom-deps | phantom-dep:@goldstack/utils-package-config-embedded | AI (phantom-deps): Same-org monorepo dep; phantom detection is a stable false positive here. | ai |
Versions (showing 51 of 71)
| Version | Deps | Published |
|---|---|---|
| 0.1.78 | 12 / 10 | |
| 0.1.77 | 12 / 10 | |
| 0.1.76 | 12 / 10 | |
| 0.1.75 | 12 / 10 | |
| 0.1.74 | 12 / 10 | |
| 0.1.73 | 12 / 10 | |
| 0.1.72 | 12 / 10 | |
| 0.1.70 | 12 / 10 | |
| 0.1.68 | 12 / 10 | |
| 0.1.67 | 12 / 10 | |
| 0.1.64 | 12 / 10 | |
| 0.1.63 | 12 / 10 | |
| 0.1.62 | 12 / 10 | |
| 0.1.61 | 12 / 10 | |
| 0.1.60 | 12 / 10 | |
| 0.1.59 | 12 / 10 | |
| 0.1.58 | 12 / 10 | |
| 0.1.57 | 12 / 10 | |
| 0.1.56 | 12 / 10 | |
| 0.1.55 | 12 / 10 | |
| 0.1.53 | 12 / 10 | |
| 0.1.51 | 12 / 11 | |
| 0.1.50 | 12 / 11 | |
| 0.1.49 | 12 / 11 | |
| 0.1.48 | 12 / 11 | |
| 0.1.47 | 12 / 11 | |
| 0.1.46 | 12 / 11 | |
| 0.1.45 | 12 / 11 | |
| 0.1.44 | 12 / 11 | |
| 0.1.43 | 12 / 11 | |
| 0.1.42 | 12 / 11 | |
| 0.1.41 | 12 / 11 | |
| 0.1.40 | 12 / 11 | |
| 0.1.39 | 12 / 11 | |
| 0.1.38 | 12 / 11 | |
| 0.1.37 | 12 / 11 | |
| 0.1.36 | 12 / 11 | |
| 0.1.35 | 12 / 11 | |
| 0.1.34 | 12 / 11 | |
| 0.1.33 | 12 / 11 | |
| 0.1.32 | 12 / 11 | |
| 0.1.31 | 12 / 11 | |
| 0.1.30 | 12 / 11 | |
| 0.1.29 | 12 / 11 | |
| 0.1.28 | 12 / 11 | |
| 0.1.27 | 12 / 11 | |
| 0.1.26 | 12 / 11 | |
| 0.1.25 | 12 / 11 | |
| 0.1.24 | 12 / 11 | |
| 0.1.23 | 12 / 11 | |
| 0.1.22 | 12 / 11 |
v0.1.78
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.77
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.76
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.75
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.74
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.63
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.62
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.61
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.59
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.57
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.56
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.55
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.53
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.51
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.49
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.48
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.47
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.46
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.45
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.43
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.41
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.36
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.35
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.34
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.31
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.30
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.29
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.28
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.27
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.26
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.25
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.24
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.23
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.22
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.