← Home

@granite-js/deployment-manager

41
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

jingjing2222heecheolghleegronxbgranite-bot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/sts-TBWJ374A.js AI (source-diff): Bundled AWS SDK STS client; minification of devDependencies is expected for this build tool package. ai

Versions (showing 41 of 41)

Version Deps Published
1.0.37 0 / 11
1.0.36 0 / 11
1.0.35 0 / 11
1.0.34 0 / 11
1.0.33 0 / 11
1.0.32 0 / 11
1.0.31 0 / 11
1.0.30 0 / 11
1.0.29 0 / 11
1.0.28 0 / 11
1.0.27 0 / 11
1.0.26 0 / 11
1.0.25 0 / 11
1.0.24 0 / 11
1.0.23 0 / 11
1.0.22 0 / 11
1.0.21 0 / 11
1.0.20 0 / 11
1.0.19 0 / 11
1.0.18 0 / 11
1.0.17 0 / 11
1.0.16 0 / 11
1.0.15 0 / 11
1.0.14 0 / 11
1.0.13 0 / 11
1.0.12 0 / 11
1.0.11 0 / 11
1.0.10 0 / 11
1.0.9 0 / 11
1.0.8 0 / 11
1.0.7 0 / 11
1.0.6 0 / 11
1.0.5 0 / 11
1.0.4 0 / 11
1.0.3 0 / 11
1.0.2 0 / 11
1.0.1 0 / 11
0.1.34 0 / 11
0.1.33 0 / 11
0.1.32 0 / 11
0.1.31 0 / 11

v1.0.37

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.36

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.35

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.34

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.