← Home

@hedystia/ws

15
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

zastinian

Keywords

hedystiawebsocketwsbunnodejsnodedenorealtimeframework

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): No behavior change; still CI-attested, trusted publisher track record. ai
publish-pattern rapid-publish AI (publish-pattern): Benign rapid patch release with no diff; consistent with trusted publisher. ai
typosquat typosquat.levenshtein:qs AI (typosquat): Scoped @hedystia/ws is a WebSocket wrapper, not a typosquat of qs; Levenshtein match is coincidental. ai
typosquat typosquat.levenshtein:pg AI (typosquat): Same reasoning — scoped WebSocket package, no relation to pg. ai

Versions (showing 15 of 15)

Version Deps Published
2.3.22 0 / 2
2.3.21 0 / 2
2.3.20 0 / 2
2.3.19 0 / 2
2.3.18 0 / 2
2.3.17 0 / 2
2.3.9 0 / 2
2.3.8 0 / 2
2.3.7 0 / 2
2.3.6 0 / 2
2.3.5 0 / 2
2.3.4 0 / 2
2.3.3 1 / 3
2.3.2 1 / 3
2.3.1 1 / 3

v2.3.22

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: zastinian.

v2.3.21

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: zastinian.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.20

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: zastinian.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.19

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: zastinian.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.18

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: zastinian.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.17

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.