← Home

@graphql-mesh/hmac-upstream-signature

14
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

urigodotansimhaardatanenisdenjotheguild-bot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:tslib AI (phantom-deps): Known implicit dependency; stable across versions. ai
phantom-deps phantom-dep:@graphql-mesh/cross-helpers AI (phantom-deps): Same-org scope; implicit dependency pattern in monorepo. ai

Versions (showing 14 of 14)

Version Deps Published
2.0.13 7 / 5
2.0.12 7 / 5
2.0.11 7 / 5
2.0.10 7 / 5
2.0.9 8 / 4
2.0.8 8 / 4
2.0.7 8 / 4
2.0.6 8 / 4
2.0.5 8 / 4
2.0.4 8 / 4
2.0.3 8 / 4
2.0.2 8 / 4
2.0.1 8 / 4
2.0.0 8 / 4

v2.0.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.