@goldstack/template-s3-cli
Building blocks for linking a package to an AWS S3 bucket.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@goldstack/utils-package-config | AI (dependencies): Same-org sibling dependency in goldstack monorepo; stable pattern across versions. | ai | |
| dependencies | unvetted-dep:@goldstack/utils-sh | AI (dependencies): Same-org sibling dependency in goldstack monorepo; stable pattern across versions. | ai | |
| dependencies | unvetted-dep:@goldstack/utils-cli | AI (dependencies): Same-org sibling dependency in goldstack monorepo; stable pattern across versions. | ai | |
| dependencies | unvetted-dep:@goldstack/utils-log | AI (dependencies): Same-org sibling dependency in goldstack monorepo; stable pattern across versions. | ai | |
| dependencies | unvetted-dep:@goldstack/utils-docker | AI (dependencies): Same-org sibling dependency in goldstack monorepo; stable pattern across versions. | ai | |
| dependencies | unvetted-dep:@goldstack/utils-package | AI (dependencies): Same-org sibling dependency in goldstack monorepo; stable pattern across versions. | ai | |
| dependencies | unvetted-dep:@goldstack/utils-template | AI (dependencies): Same-org sibling dependency in goldstack monorepo; stable pattern across versions. | ai | |
| dependencies | unvetted-dep:@goldstack/utils-s3-deployment | AI (dependencies): Same-org sibling dependency in goldstack monorepo; stable pattern across versions. | ai | |
| phantom-deps | phantom-dep:@goldstack/utils-log | AI (phantom-deps): Same-org sibling dep in goldstack monorepo; phantom detection is a false positive here. | ai | |
| provenance | no-provenance | AI (provenance): Established goldstack monorepo package; no provenance is consistent across all 113 versions. | ai | |
| phantom-deps | phantom-dep:@goldstack/utils-s3-deployment | AI (phantom-deps): Same-org dependency; phantom-dep heuristic false positive for this monorepo package. | ai | |
| phantom-deps | phantom-dep:@goldstack/utils-docker | AI (phantom-deps): Same-org dependency; phantom-dep heuristic false positive for this monorepo package. | ai | |
| phantom-deps | phantom-dep:@goldstack/utils-sh | AI (phantom-deps): Same-org dependency; phantom-dep heuristic false positive for this monorepo package. | ai | |
| phantom-deps | phantom-dep:source-map-support | AI (phantom-deps): source-map-support is a declared runtime dep commonly used via require hook in config; stable false positive. | ai | |
| phantom-deps | phantom-dep:@goldstack/utils-template | AI (phantom-deps): Same-org dependency; phantom-dep heuristic false positive for this monorepo package. | ai |
Versions (showing 25 of 25)
| Version | Deps | Published |
|---|---|---|
| 0.6.104 | 13 / 10 | |
| 0.6.103 | 13 / 10 | |
| 0.6.102 | 13 / 10 | |
| 0.6.101 | 13 / 10 | |
| 0.6.97 | 13 / 10 | |
| 0.6.95 | 13 / 10 | |
| 0.6.94 | 13 / 10 | |
| 0.6.89 | 13 / 10 | |
| 0.6.88 | 13 / 10 | |
| 0.6.87 | 13 / 10 | |
| 0.6.86 | 13 / 10 | |
| 0.6.78 | 13 / 12 | |
| 0.6.77 | 13 / 12 | |
| 0.6.76 | 13 / 12 | |
| 0.6.74 | 13 / 12 | |
| 0.6.72 | 13 / 12 | |
| 0.6.70 | 13 / 12 | |
| 0.6.69 | 13 / 12 | |
| 0.6.67 | 13 / 12 | |
| 0.6.66 | 13 / 12 | |
| 0.6.65 | 13 / 12 | |
| 0.6.64 | 13 / 12 | |
| 0.6.63 | 13 / 12 | |
| 0.6.62 | 13 / 12 | |
| 0.6.58 | 13 / 12 |
v0.6.104
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.103
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.102
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.101
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.97
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.95
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.94
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.89
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.88
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.87
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.86
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.78
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.77
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.76
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.74
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.72
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.70
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.69
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.67
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.66
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.65
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.64
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.63
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.62
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.58
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.