← Home

@helia/mfs

11
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

npm-service-account-ipfsachingbrain

Keywords

IPFS

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Publisher change from npm-service-account-ipfs to GitHub Actions reflects a legitimate CI/CD migration for the official ipfs/helia monorepo; SLSA provenance attestation confirms integrity. ai
publish-pattern dormant-publish AI (publish-pattern): Dormancy is consistent with a monorepo publishing workflow migration; SLSA provenance and official ipfs org repo confirm legitimacy. ai
typosquat typosquat.levenshtein:qs AI (typosquat): @helia/mfs is the official IPFS Helia Mutable File System package, scoped under @helia. No reasonable confusion with 'qs' is possible; this is a persistent false positive for this package. ai

Versions (showing 11 of 11)

Version Deps Published
7.1.1 9 / 12
7.1.0 9 / 12
7.0.5 9 / 12
7.0.4 9 / 12
7.0.3 9 / 12
7.0.2 9 / 12
7.0.1 9 / 12
7.0.0 9 / 12
6.0.4 8 / 12
6.0.3 8 / 12
6.0.2 8 / 12

v7.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.