← Home

@graphql-mesh/cache-inmemory-lru

57
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

urigodotansimhaardatanenisdenjotheguild-bot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition from ardatan to GitHub Actions CI/CD is consistent with SLSA-attested automated publishing in the graphql-mesh monorepo. ai
publish-pattern dormant-publish AI (publish-pattern): Dormancy explained by CI/CD pipeline migration; SLSA attestation confirms legitimate publish origin. ai
phantom-deps phantom-dep:tslib AI (phantom-deps): tslib is a declared runtime dependency used as implicit polyfill; standard pattern for this package. ai
npm-metadata no-description AI (npm-metadata): Monorepo sub-package; missing description is consistent across all graphql-mesh cache packages. ai

Versions (showing 57 of 57)

Version Deps Published
0.8.39 4 / 0
0.8.38 4 / 0
0.8.37 4 / 0
0.8.36 4 / 0
0.8.35 4 / 0
0.8.34 4 / 0
0.8.33 4 / 0
0.8.32 4 / 0
0.8.31 4 / 0
0.8.30 4 / 0
0.8.29 4 / 0
0.8.28 4 / 0
0.8.27 4 / 0
0.8.26 4 / 0
0.8.25 4 / 0
0.8.24 4 / 0
0.8.23 4 / 0
0.8.22 4 / 0
0.8.21 4 / 0
0.8.20 4 / 0
0.8.19 4 / 0
0.8.18 4 / 0
0.8.17 4 / 0
0.8.16 4 / 0
0.8.15 4 / 0
0.8.14 4 / 0
0.8.13 4 / 0
0.8.12 4 / 0
0.8.11 4 / 0
0.8.10 4 / 0
0.8.9 4 / 0
0.8.8 4 / 0
0.8.7 4 / 0
0.8.6 4 / 0
0.8.5 4 / 0
0.8.4 4 / 0
0.8.3 4 / 0
0.8.2 4 / 0
0.8.1 4 / 0
0.8.0 4 / 0
0.7.2 4 / 0
0.7.1 4 / 0
0.7.0 4 / 0
0.0.14 4 / 0
0.0.13 4 / 0
0.0.12 4 / 0
0.0.11 4 / 0
0.0.10 4 / 0
0.0.9 4 / 0
0.0.8 4 / 0
0.0.7 4 / 0
0.0.6 4 / 0
0.0.5 4 / 0
0.0.4 4 / 0
0.0.3 4 / 0
0.0.2 4 / 0
0.0.1 4 / 0

v0.8.39

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.14

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.