← Home

@jupyter/ydoc

Jupyter document structures for collaborative editing using YJS

44
Versions
BSD-3-Clause
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

fcollonvalvidartfdavidbrochartjtpioblink1073darianajbozarthzsailerjupyter-release-botjupyter-server-release-botkrassowski

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): Metadata-only issue; publisher is a known Jupyter maintainer with clean history. No code changes in this version. ai
provenance no-provenance AI (provenance): Informational; many legitimate packages lack Sigstore provenance. Not a security risk for this established package. ai
provenance publisher-changed AI (provenance): Transition from jupyter-server-release-bot to GitHub Actions is a CI bot migration within the Jupyter org, confirmed by SLSA provenance. ai
bogus-package bogus-package AI (bogus-package): Inflated semver, short README, and no keywords are all expected for an official Jupyter scoped package migrated/extracted from a monorepo. Not indicative of spam or malice. ai
dependencies unvetted-dep:@jupyterlab/nbformat AI (dependencies): Official JupyterLab package for notebook format definitions; expected dependency for a Jupyter document library. ai
dependencies unvetted-dep:yjs AI (dependencies): yjs is a well-known CRDT library; a core dependency of @jupyter/ydoc by design. ai
dependencies unvetted-dep:y-protocols AI (dependencies): y-protocols is the standard companion to yjs; legitimate and expected dependency. ai

Versions (showing 44 of 44)

Version Deps Published
4.1.1 6 / 13
4.1.0 6 / 13
4.0.0 6 / 13
3.5.0 6 / 13
3.4.1 6 / 13
3.4.0 6 / 13
3.3.6 6 / 13
3.3.5 6 / 13
3.3.4 6 / 13
3.3.3 6 / 13
3.3.2 6 / 13
3.3.1 6 / 13
3.3.0 6 / 13
3.2.1 6 / 13
3.2.0 6 / 13
3.1.0 6 / 13
3.0.5 6 / 13
3.0.4 6 / 13
3.0.3 6 / 13
3.0.2 6 / 13
3.0.1 6 / 13
3.0.0 6 / 13
2.1.5 6 / 13
2.1.4 6 / 13
2.1.3 6 / 13
2.1.2 6 / 13
2.1.1 6 / 13
2.1.0 6 / 13
2.0.1 6 / 13
2.0.0 6 / 13
1.1.1 6 / 13
1.1.0 6 / 13
1.0.2 6 / 13
1.0.1 6 / 13
1.0.0 6 / 13
0.3.4 6 / 14
0.3.3 6 / 14
0.3.2 6 / 14
0.3.1 6 / 14
0.3.0 6 / 14
0.2.5 6 / 11
0.2.4 6 / 11
0.2.3 6 / 11
0.2.2 6 / 11

v4.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.