@goldstack/template-s3
Building blocks for linking a package to an AWS S3 bucket.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@goldstack/utils-package-config-embedded | AI (dependencies): Same org monorepo dependency; stable pattern across all goldstack packages. | ai | |
| dependencies | unvetted-dep:@goldstack/utils-log | AI (dependencies): Same org monorepo dependency; stable pattern across all goldstack packages. | ai | |
| dependencies | unvetted-dep:@goldstack/utils-esbuild | AI (dependencies): Same org monorepo dependency; stable pattern across all goldstack packages. | ai | |
| dependencies | unvetted-dep:@goldstack/utils-package | AI (dependencies): Same org monorepo dependency; stable pattern across all goldstack packages. | ai | |
| dependencies | unvetted-dep:@goldstack/utils-template | AI (dependencies): Same org monorepo dependency; stable pattern across all goldstack packages. | ai | |
| dependencies | unvetted-dep:mock-aws-s3-v3 | AI (dependencies): Testing/mock library pinned to exact version; consistent with test infrastructure use in this package. | ai | |
| dependencies | unvetted-dep:@goldstack/infra | AI (dependencies): Same org monorepo dependency; stable pattern across all goldstack packages. | ai | |
| dependencies | unvetted-dep:@goldstack/infra-aws | AI (dependencies): Same org monorepo dependency; stable pattern across all goldstack packages. | ai | |
| phantom-deps | phantom-dep:mock-aws-s3-v3 | AI (phantom-deps): Referenced in config/test setup; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:source-map-support | AI (phantom-deps): Loaded via config convention, not direct import; stable false positive. | ai | |
| phantom-deps | phantom-dep:@goldstack/utils-template | AI (phantom-deps): Same-org package loaded by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/types | AI (phantom-deps): Framework-scoped AWS SDK type package; stable false positive for this package. | ai |
Versions (showing 13 of 13)
| Version | Deps | Published |
|---|---|---|
| 0.5.81 | 16 / 10 | |
| 0.5.78 | 16 / 10 | |
| 0.5.73 | 16 / 10 | |
| 0.5.71 | 16 / 10 | |
| 0.5.70 | 16 / 10 | |
| 0.5.67 | 16 / 10 | |
| 0.5.66 | 16 / 10 | |
| 0.5.55 | 16 / 12 | |
| 0.5.51 | 16 / 12 | |
| 0.5.44 | 16 / 12 | |
| 0.5.43 | 16 / 12 | |
| 0.5.41 | 16 / 12 | |
| 0.5.36 | 16 / 12 |
v0.5.81
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.5.78
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.5.73
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.5.71
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.5.70
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.5.67
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.5.66
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.5.55
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.5.51
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.5.44
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.5.43
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.5.41
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.5.36
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.