@goldstack/template-s3
Building blocks for linking a package to an AWS S3 bucket.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@goldstack/utils-package-config-embedded | AI (dependencies): Same org monorepo dependency; stable pattern across all goldstack packages. | ai | |
| dependencies | unvetted-dep:@goldstack/utils-log | AI (dependencies): Same org monorepo dependency; stable pattern across all goldstack packages. | ai | |
| dependencies | unvetted-dep:@goldstack/utils-esbuild | AI (dependencies): Same org monorepo dependency; stable pattern across all goldstack packages. | ai | |
| dependencies | unvetted-dep:@goldstack/utils-package | AI (dependencies): Same org monorepo dependency; stable pattern across all goldstack packages. | ai | |
| dependencies | unvetted-dep:@goldstack/utils-template | AI (dependencies): Same org monorepo dependency; stable pattern across all goldstack packages. | ai | |
| dependencies | unvetted-dep:mock-aws-s3-v3 | AI (dependencies): Testing/mock library pinned to exact version; consistent with test infrastructure use in this package. | ai | |
| dependencies | unvetted-dep:@goldstack/infra | AI (dependencies): Same org monorepo dependency; stable pattern across all goldstack packages. | ai | |
| dependencies | unvetted-dep:@goldstack/infra-aws | AI (dependencies): Same org monorepo dependency; stable pattern across all goldstack packages. | ai | |
| phantom-deps | phantom-dep:mock-aws-s3-v3 | AI (phantom-deps): Referenced in config/test setup; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:source-map-support | AI (phantom-deps): Loaded via config convention, not direct import; stable false positive. | ai | |
| phantom-deps | phantom-dep:@goldstack/utils-template | AI (phantom-deps): Same-org package loaded by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/types | AI (phantom-deps): Framework-scoped AWS SDK type package; stable false positive for this package. | ai |
Versions (showing 51 of 54)
| Version | Deps | Published |
|---|---|---|
| 0.5.85 | 16 / 10 | |
| 0.5.84 | 16 / 10 | |
| 0.5.83 | 16 / 10 | |
| 0.5.82 | 16 / 10 | |
| 0.5.81 | 16 / 10 | |
| 0.5.78 | 16 / 10 | |
| 0.5.73 | 16 / 10 | |
| 0.5.71 | 16 / 10 | |
| 0.5.70 | 16 / 10 | |
| 0.5.67 | 16 / 10 | |
| 0.5.66 | 16 / 10 | |
| 0.5.55 | 16 / 12 | |
| 0.5.51 | 16 / 12 | |
| 0.5.48 | 16 / 12 | |
| 0.5.47 | 16 / 12 | |
| 0.5.46 | 16 / 12 | |
| 0.5.45 | 16 / 12 | |
| 0.5.44 | 16 / 12 | |
| 0.5.43 | 16 / 12 | |
| 0.5.42 | 16 / 12 | |
| 0.5.41 | 16 / 12 | |
| 0.5.40 | 16 / 12 | |
| 0.5.39 | 16 / 12 | |
| 0.5.38 | 16 / 12 | |
| 0.5.37 | 16 / 12 | |
| 0.5.36 | 16 / 12 | |
| 0.5.35 | 16 / 12 | |
| 0.5.34 | 16 / 12 | |
| 0.5.33 | 16 / 12 | |
| 0.5.32 | 16 / 12 | |
| 0.5.31 | 16 / 12 | |
| 0.5.30 | 16 / 12 | |
| 0.5.29 | 16 / 12 | |
| 0.5.28 | 16 / 12 | |
| 0.5.27 | 16 / 12 | |
| 0.5.26 | 16 / 12 | |
| 0.5.25 | 16 / 12 | |
| 0.5.24 | 16 / 12 | |
| 0.5.23 | 16 / 12 | |
| 0.5.22 | 16 / 12 | |
| 0.5.21 | 16 / 12 | |
| 0.5.20 | 16 / 12 | |
| 0.5.19 | 16 / 12 | |
| 0.5.18 | 16 / 12 | |
| 0.5.17 | 16 / 12 | |
| 0.5.16 | 16 / 12 | |
| 0.5.15 | 16 / 12 | |
| 0.5.14 | 16 / 12 | |
| 0.5.13 | 16 / 12 | |
| 0.5.12 | 16 / 12 | |
| 0.5.11 | 16 / 12 |
v0.5.85
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.84
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.83
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.82
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.48
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.47
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.46
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.45
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.42
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.40
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.39
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.38
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.37
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.35
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.34
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.5.33
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.32
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.31
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.30
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.29
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.28
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.27
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.26
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.25
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.24
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.23
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.22
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.21
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.20
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.19
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.18
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.17
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.16
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.