← Home

@graphql-mesh/plugin-prometheus

23
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

urigodotansimhaardatanenisdenjotheguild-bot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:tslib AI (phantom-deps): tslib is a standard TypeScript runtime helper; implicit dependency pattern stable for this package. ai
phantom-deps phantom-dep:@graphql-mesh/cross-helpers AI (phantom-deps): Same org scope; used as a build/runtime helper across the graphql-mesh ecosystem. ai

Versions (showing 23 of 23)

Version Deps Published
2.1.56 9 / 4
2.1.55 9 / 4
2.1.54 9 / 4
2.1.53 9 / 4
2.1.52 9 / 4
2.1.51 9 / 4
2.1.50 9 / 4
2.1.49 9 / 4
2.1.48 9 / 4
2.1.47 9 / 4
2.1.46 9 / 4
2.1.45 9 / 4
2.1.44 9 / 4
2.1.43 9 / 4
2.1.42 9 / 4
2.1.41 9 / 4
2.1.23 9 / 4
2.1.5 9 / 4
2.0.12 9 / 4
2.0.9 9 / 4
2.0.6 9 / 4
2.0.1 9 / 4
2.0.0 9 / 4

v2.1.56

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.55

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.54

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.53

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.52

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.51

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.50

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.49

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.