@graphql-mesh/cli
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions CI publisher is confirmed by SLSA provenance attestation; stable pattern for this package going forward. | ai | |
| dependencies | unvetted-dep:@graphql-mesh/include | AI (dependencies): First-party @graphql-mesh monorepo package; stable pattern across all versions. | ai | |
| dependencies | unvetted-dep:@graphql-mesh/incontext-sdk-codegen | AI (dependencies): First-party @graphql-mesh monorepo package; stable pattern across all versions. | ai | |
| phantom-deps | phantom-dep:change-case | AI (phantom-deps): Used in codegen config context; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:graphql-tag | AI (phantom-deps): Peer/config-level dep for GraphQL tooling; stable false positive. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped package @graphql-mesh/cli; levenshtein match to 'joi' is a false positive with no plausible impersonation intent. | ai | |
| phantom-deps | phantom-dep:json-bigint-patch | AI (phantom-deps): Side-effect dep applied via import; stable false positive. | ai | |
| phantom-deps | phantom-dep:graphql-import-node | AI (phantom-deps): Side-effect/config dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:pascal-case | AI (phantom-deps): Codegen utility dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:mkdirp | AI (phantom-deps): CLI tooling dep used in build/config scripts, not a direct import; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:rimraf | AI (phantom-deps): CLI tooling dep used in build/config scripts; stable false positive. | ai |
Versions (showing 44 of 144)
| Version | Deps | Published |
|---|---|---|
| 0.96.0 | 31 / 0 | |
| 0.95.4 | 31 / 0 | |
| 0.95.3 | 31 / 0 | |
| 0.95.2 | 31 / 0 | |
| 0.95.1 | 31 / 0 | |
| 0.95.0 | 31 / 0 | |
| 0.94.3 | 31 / 0 | |
| 0.94.2 | 31 / 0 | |
| 0.94.1 | 31 / 0 | |
| 0.94.0 | 31 / 0 | |
| 0.93.0 | 31 / 0 | |
| 0.92.10 | 31 / 0 | |
| 0.92.9 | 31 / 0 | |
| 0.92.8 | 31 / 0 | |
| 0.92.7 | 31 / 0 | |
| 0.92.6 | 31 / 0 | |
| 0.92.5 | 31 / 0 | |
| 0.92.4 | 31 / 0 | |
| 0.92.3 | 31 / 0 | |
| 0.92.2 | 30 / 0 | |
| 0.92.1 | 30 / 0 | |
| 0.92.0 | 30 / 0 | |
| 0.91.2 | 31 / 0 | |
| 0.91.1 | 31 / 0 | |
| 0.91.0 | 31 / 0 | |
| 0.90.12 | 32 / 0 | |
| 0.90.11 | 32 / 0 | |
| 0.90.10 | 32 / 0 | |
| 0.90.9 | 32 / 0 | |
| 0.90.8 | 32 / 0 | |
| 0.90.7 | 32 / 0 | |
| 0.82.35 | 33 / 0 | |
| 0.82.34 | 33 / 0 | |
| 0.82.33 | 33 / 0 | |
| 0.82.32 | 33 / 0 | |
| 0.82.31 | 33 / 0 | |
| 0.82.30 | 33 / 0 | |
| 0.82.29 | 33 / 0 | |
| 0.82.28 | 33 / 0 | |
| 0.82.27 | 33 / 0 | |
| 0.82.25 | 33 / 0 | |
| 0.82.24 | 33 / 0 | |
| 0.82.23 | 33 / 0 | |
| 0.82.22 | 33 / 0 |
v0.96.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.95.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.95.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.95.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.95.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.95.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.94.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.94.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.94.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.94.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.93.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.92.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.92.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.92.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.92.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.92.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.92.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.92.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.92.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.92.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.92.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.92.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.91.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.91.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.91.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.90.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.90.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.90.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.90.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.90.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.90.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.82.35
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.82.34
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.82.33
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.82.32
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.82.31
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.82.30
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.82.29
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.82.28
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.82.27
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.82.25
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.82.24
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.82.23
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.82.22
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.