← Home

@jupyterlab/git

A JupyterLab extension for version control using git

14
Versions
BSD-3-Clause
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

darianblink1073jasongroutsylvaincorlayminrkzsailertelamonianfcollonvaljtpiogoanpecambektasloichuderkrassowskijupyter-server-release-botjupyterlab-release-botrrosio

Keywords

JupyterJupyterLabjupyterlab-extensionGit

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
maintainer-change maintainer-takeover AI (maintainer-change): Legitimate JupyterLab org maintainer transition, long-lived on npm, provenance-attested. ai
dependencies unvetted-dep:@material-ui/lab AI (dependencies): Established UI library, standard for JupyterLab extensions. ai
provenance publisher-changed-stale AI (provenance): Publisher change is from 2020, long-stable, not a takeover pattern. ai
phantom-deps phantom-dep:@jupyterlab/nbformat AI (phantom-deps): Same-org JupyterLab package, typing/type-only usage. ai
publish-pattern new-deps-added AI (publish-pattern): Adds official @jupyterlab/ui-components, a first-party sibling package. ai
maintainer-change maintainer-added AI (maintainer-change): Known JupyterLab org maintainers added; consistent with legitimate project team growth. ai
publish-pattern dormant-publish AI (publish-pattern): Official jupyterlab org package with SLSA provenance; long gap between releases is plausible for a mature extension. ai
dependencies unvetted-dep:nbdime-jupyterlab AI (dependencies): nbdime-jupyterlab is the JupyterLab integration of nbdime; stable dependency for this package. ai
dependencies unvetted-dep:nbdime AI (dependencies): nbdime is a well-known Jupyter project; stable dependency for this package. ai
typosquat typosquat.levenshtein:got AI (typosquat): Established JupyterLab extension; name similarity to 'got' is coincidental, not a typosquat. ai
phantom-deps phantom-dep:@jupyterlab/terminal AI (phantom-deps): Same-org JupyterLab peer dependency; config-level reference is expected. ai
typosquat typosquat.levenshtein:vite AI (typosquat): Established JupyterLab extension; name similarity to 'vite' is coincidental, not a typosquat. ai
phantom-deps phantom-dep:@mui/lab AI (phantom-deps): JupyterLab singleton/shared-package pattern; declared for bundling config, not direct import. ai
phantom-deps phantom-dep:react-dom AI (phantom-deps): Peer/config dependency in JupyterLab extension pattern. ai
phantom-deps phantom-dep:@mui/styles AI (phantom-deps): Referenced in config files per JupyterLab extension pattern. ai
phantom-deps phantom-dep:@emotion/react AI (phantom-deps): Config-level dependency in JupyterLab extension pattern. ai
phantom-deps phantom-dep:@emotion/styled AI (phantom-deps): Config-level dependency in JupyterLab extension pattern. ai
phantom-deps phantom-dep:nbdime-jupyterlab AI (phantom-deps): Declared as singleton in jupyterlab sharedPackages config, not directly imported. ai
phantom-deps phantom-dep:@jupyterlab/console AI (phantom-deps): Same-org JupyterLab peer dependency; config-level reference is expected. ai

Versions (showing 14 of 14)

Version Deps Published
0.51.1 39 / 45
0.51.0 39 / 45
0.50.2 39 / 44
0.50.1 39 / 44
0.22.0 29 / 33
0.20.0 22 / 30
0.10.1 19 / 30
0.10.0 19 / 28
0.9.1 14 / 25
0.9.0 14 / 25
0.8.2 13 / 22
0.8.1 13 / 22
0.8.0 13 / 22
0.7.0 12 / 22

v0.51.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.51.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.50.2

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: fcollonval → jupyterlab-release-bot (on 2024-10-29, now via trusted publisher with provenance) provenance

This version was published by a different npm account (jupyterlab-release-bot) than the most recent previously approved version (fcollonval) on 2024-10-29, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.50.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.22.0

2 findings
MEDIUM Publisher changed: jaipreets → fcollonval (on 2020-10-04, unremoved on npm for 2119d) provenance

This version was published by a different npm account (fcollonval) than the most recent previously approved version (jaipreets) on 2020-10-04. It has since remained available on npm for 2119 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.20.0

2 findings
MEDIUM Publisher changed: jaipreets → fcollonval (on 2020-05-05, unremoved on npm for 2271d) provenance

This version was published by a different npm account (fcollonval) than the most recent previously approved version (jaipreets) on 2020-05-05. It has since remained available on npm for 2271 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.1

2 findings
MEDIUM Publisher changed: jaipreets → fcollonval (on 2020-04-25, unremoved on npm for 2281d) provenance

This version was published by a different npm account (fcollonval) than the most recent previously approved version (jaipreets) on 2020-04-25. It has since remained available on npm for 2281 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.0

2 findings
MEDIUM Publisher changed: jaipreets → telamonian (on 2020-03-26, unremoved on npm for 2311d) provenance

This version was published by a different npm account (telamonian) than the most recent previously approved version (jaipreets) on 2020-03-26. It has since remained available on npm for 2311 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.1

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: jaipreets → blink1073 (on 2020-03-24, known maintainer) provenance

This version was published by a different npm account (blink1073) than the most recent previously approved version (jaipreets) on 2020-03-24, but blink1073 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.9.0

2 findings
MEDIUM Publisher changed: jaipreets → telamonian (on 2019-12-04, unremoved on npm for 2424d) provenance

This version was published by a different npm account (telamonian) than the most recent previously approved version (jaipreets) on 2019-12-04. It has since remained available on npm for 2424 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.8.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.8.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.8.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.