← Home

@graphql-hive/plugin-aws-sigv4

51
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

dotansimhakamilkisielaardatanenisdenjotheguild-bot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance no-provenance AI (provenance): No provenance is common; publisher has strong track record and repo URL is verifiable. ai
npm-metadata no-description AI (npm-metadata): The Guild org packages commonly omit descriptions; not a malware indicator here. ai
phantom-deps phantom-dep:tslib AI (phantom-deps): tslib is a declared runtime dependency; phantom-dep is a false positive for this package. ai

Versions (showing 51 of 59)

View all versions
Version Deps Published
2.0.58 5 / 6
2.0.57 5 / 6
2.0.56 5 / 6
2.0.55 5 / 6
2.0.54 5 / 6
2.0.53 5 / 6
2.0.52 5 / 6
2.0.51 5 / 6
2.0.50 5 / 6
2.0.49 5 / 6
2.0.48 5 / 6
2.0.47 5 / 6
2.0.46 5 / 6
2.0.45 5 / 6
2.0.44 5 / 6
2.0.43 5 / 6
2.0.42 5 / 6
2.0.41 5 / 6
2.0.40 5 / 6
2.0.39 5 / 6
2.0.38 5 / 6
2.0.37 5 / 6
2.0.36 5 / 6
2.0.35 5 / 6
2.0.34 5 / 6
2.0.33 5 / 6
2.0.32 5 / 6
2.0.31 5 / 6
2.0.30 5 / 6
2.0.29 5 / 6
2.0.28 5 / 6
2.0.27 5 / 6
2.0.26 5 / 6
2.0.25 5 / 6
2.0.24 5 / 6
2.0.23 5 / 6
2.0.22 5 / 6
2.0.21 5 / 6
2.0.20 5 / 6
2.0.19 5 / 6
2.0.18 5 / 6
2.0.17 5 / 6
2.0.16 5 / 6
2.0.15 5 / 6
2.0.14 5 / 6
2.0.13 5 / 6
2.0.12 5 / 6
2.0.11 5 / 6
2.0.10 5 / 6
2.0.9 5 / 6
2.0.8 5 / 6

v2.0.58

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.57

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.56

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.55

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.54

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.53

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.52

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.51

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.