← Home

@graphql-hive/gateway

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

dotansimhakamilkisielaardatanenisdenjotheguild-bot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@opentelemetry/sdk-logs AI (phantom-deps): OTel config reference; stable false positive. ai
phantom-deps phantom-dep:tslib AI (phantom-deps): tslib is a known implicit runtime dep for TypeScript-compiled packages. ai
phantom-deps phantom-dep:commander AI (phantom-deps): CLI tool; commander referenced in config/bin files, stable pattern for this package. ai
phantom-deps phantom-dep:@envelop/core AI (phantom-deps): Referenced in config files; standard pattern for graphql-hive gateway. ai
phantom-deps phantom-dep:@opentelemetry/api AI (phantom-deps): OTel peer/config reference; stable false positive for this package. ai
phantom-deps phantom-dep:@opentelemetry/core AI (phantom-deps): OTel config reference; stable false positive. ai
phantom-deps phantom-dep:@graphql-hive/importer AI (phantom-deps): Same org scope; referenced in config files, stable false positive. ai
phantom-deps phantom-dep:@opentelemetry/api-logs AI (phantom-deps): OTel config reference; stable false positive. ai
phantom-deps phantom-dep:@opentelemetry/sdk-metrics AI (phantom-deps): OTel config reference; stable false positive. ai
phantom-deps phantom-dep:@graphql-mesh/cross-helpers AI (phantom-deps): Config file reference; stable false positive for this package. ai
phantom-deps phantom-dep:@opentelemetry/context-zone AI (phantom-deps): OTel config reference; stable false positive. ai
phantom-deps phantom-dep:@opentelemetry/propagator-b3 AI (phantom-deps): OTel config reference; stable false positive. ai
phantom-deps phantom-dep:@opentelemetry/exporter-jaeger AI (phantom-deps): OTel config reference; stable false positive. ai
phantom-deps phantom-dep:@opentelemetry/exporter-zipkin AI (phantom-deps): OTel config reference; stable false positive. ai
phantom-deps phantom-dep:@opentelemetry/propagator-jaeger AI (phantom-deps): OTel config reference; stable false positive. ai
phantom-deps phantom-dep:@opentelemetry/sampler-jaeger-remote AI (phantom-deps): OTel config reference; stable false positive. ai
phantom-deps phantom-dep:@graphql-mesh/hmac-upstream-signature AI (phantom-deps): Config file reference; stable false positive for this package. ai

Versions (showing 51 of 63)

View all versions
Version Deps Published
2.8.2 54 / 23
2.8.1 54 / 23
2.8.0 54 / 23
2.7.2 54 / 23
2.7.1 54 / 23
2.7.0 54 / 23
2.5.28 52 / 23
2.5.14 52 / 23
2.5.13 52 / 23
2.5.12 52 / 23
2.5.11 52 / 23
2.5.10 52 / 23
2.5.9 52 / 23
2.5.8 52 / 23
2.5.7 52 / 23
2.5.6 52 / 23
2.5.5 52 / 23
2.5.4 52 / 23
2.5.3 53 / 23
2.5.2 53 / 23
2.5.1 53 / 23
2.5.0 53 / 23
2.4.3 53 / 22
2.4.2 53 / 22
2.4.1 53 / 22
2.4.0 53 / 22
2.3.3 53 / 22
2.3.2 53 / 22
2.3.1 53 / 22
2.3.0 53 / 22
2.2.3 53 / 22
2.2.2 53 / 22
2.2.1 53 / 22
2.2.0 53 / 22
2.1.23 52 / 22
2.1.22 52 / 22
2.1.21 52 / 22
2.1.20 52 / 22
2.1.19 52 / 22
2.1.18 52 / 22
2.1.17 52 / 22
2.1.16 52 / 22
2.1.15 52 / 22
2.1.14 52 / 22
2.1.13 52 / 22
2.1.12 52 / 22
2.1.11 52 / 22
2.1.10 52 / 22
2.1.9 52 / 22
2.1.8 52 / 22
2.1.7 52 / 22

v2.8.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.8.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.8.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.7.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.7.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.7.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.5.14

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.5.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.5.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.5.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.5.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.5.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.5.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.5.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.5.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.5.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.2.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.23

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.22

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.21

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.20

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.19

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.18

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.