@highflame/policy
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Transition from human publisher to GitHub Actions bot is a standard CI/CD automation pattern, not a compromise indicator. | ai | |
| source-diff | obfuscated-file:dist/service-schemas.gen.d.ts | AI (source-diff): Long lines are an embedded Cedar schema string constant in a .d.ts file, not obfuscated malicious code. | ai | |
| semgrep | semgrep:etc-passwd-access | AI (semgrep): Appears only in test fixtures as a string literal for Cedar policy evaluation; not executable credential access. | ai |
Versions (showing 51 of 80)
| Version | Deps | Published |
|---|---|---|
| 2.2.31 | 2 / 3 | |
| 2.2.29 | 2 / 3 | |
| 2.2.28 | 2 / 3 | |
| 2.2.27 | 2 / 3 | |
| 2.2.26 | 2 / 3 | |
| 2.2.25 | 2 / 3 | |
| 2.2.24 | 2 / 3 | |
| 2.2.23 | 2 / 3 | |
| 2.2.22 | 2 / 3 | |
| 2.2.11 | 2 / 3 | |
| 2.2.10 | 2 / 3 | |
| 2.2.9 | 2 / 3 | |
| 2.2.8 | 2 / 3 | |
| 2.2.7 | 2 / 3 | |
| 2.2.6 | 2 / 3 | |
| 2.2.5 | 2 / 3 | |
| 2.2.4 | 2 / 3 | |
| 2.2.3 | 2 / 3 | |
| 2.2.2 | 2 / 3 | |
| 2.2.1 | 2 / 3 | |
| 2.2.0 | 2 / 3 | |
| 2.1.45 | 1 / 3 | |
| 2.1.44 | 1 / 3 | |
| 2.1.43 | 1 / 3 | |
| 2.1.42 | 1 / 3 | |
| 2.1.41 | 1 / 3 | |
| 2.1.40 | 1 / 3 | |
| 2.1.39 | 1 / 3 | |
| 2.1.38 | 1 / 3 | |
| 2.1.37 | 1 / 3 | |
| 2.1.36 | 1 / 3 | |
| 2.1.35 | 1 / 3 | |
| 2.1.34 | 1 / 3 | |
| 2.1.33 | 1 / 3 | |
| 2.1.32 | 1 / 3 | |
| 2.1.31 | 1 / 3 | |
| 2.1.30 | 1 / 3 | |
| 2.1.29 | 1 / 3 | |
| 2.1.28 | 1 / 3 | |
| 2.1.26 | 1 / 3 | |
| 2.1.25 | 1 / 3 | |
| 2.1.24 | 1 / 3 | |
| 2.1.23 | 1 / 3 | |
| 2.1.22 | 1 / 3 | |
| 2.1.21 | 1 / 3 | |
| 2.1.20 | 1 / 3 | |
| 2.1.19 | 1 / 3 | |
| 2.1.18 | 1 / 3 | |
| 2.1.17 | 1 / 3 | |
| 2.1.16 | 1 / 3 | |
| 2.1.15 | 1 / 3 |
v2.2.31
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.29
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.28
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.27
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.26
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.25
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.24
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.23
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.22
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.