← Home

@iobroker/webserver

4
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

foxriver76iobluefoxbluefoxapollon77ldittmaralcalzonemcm1957

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:oauth2-server AI (dependencies): Well-known OAuth library, fits webserver's stated purpose. ai
publish-pattern dormant-publish AI (publish-pattern): Long-standing trusted maintainer with strong track record; normal maintenance cadence. ai

Versions (showing 4 of 4)

Version Deps Published
1.3.3 3 / 8
1.1.0 1 / 10
1.0.8 0 / 8
1.0.6 0 / 8

v1.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.