@jupyterlab/git
A JupyterLab extension for version control using git
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-takeover | AI (maintainer-change): Legitimate JupyterLab org maintainer transition, long-lived on npm, provenance-attested. | ai | |
| dependencies | unvetted-dep:@material-ui/lab | AI (dependencies): Established UI library, standard for JupyterLab extensions. | ai | |
| provenance | publisher-changed-stale | AI (provenance): Publisher change is from 2020, long-stable, not a takeover pattern. | ai | |
| phantom-deps | phantom-dep:@jupyterlab/nbformat | AI (phantom-deps): Same-org JupyterLab package, typing/type-only usage. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): Adds official @jupyterlab/ui-components, a first-party sibling package. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Known JupyterLab org maintainers added; consistent with legitimate project team growth. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Official jupyterlab org package with SLSA provenance; long gap between releases is plausible for a mature extension. | ai | |
| dependencies | unvetted-dep:nbdime-jupyterlab | AI (dependencies): nbdime-jupyterlab is the JupyterLab integration of nbdime; stable dependency for this package. | ai | |
| dependencies | unvetted-dep:nbdime | AI (dependencies): nbdime is a well-known Jupyter project; stable dependency for this package. | ai | |
| typosquat | typosquat.levenshtein:got | AI (typosquat): Established JupyterLab extension; name similarity to 'got' is coincidental, not a typosquat. | ai | |
| phantom-deps | phantom-dep:@jupyterlab/terminal | AI (phantom-deps): Same-org JupyterLab peer dependency; config-level reference is expected. | ai | |
| typosquat | typosquat.levenshtein:vite | AI (typosquat): Established JupyterLab extension; name similarity to 'vite' is coincidental, not a typosquat. | ai | |
| phantom-deps | phantom-dep:@mui/lab | AI (phantom-deps): JupyterLab singleton/shared-package pattern; declared for bundling config, not direct import. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): Peer/config dependency in JupyterLab extension pattern. | ai | |
| phantom-deps | phantom-dep:@mui/styles | AI (phantom-deps): Referenced in config files per JupyterLab extension pattern. | ai | |
| phantom-deps | phantom-dep:@emotion/react | AI (phantom-deps): Config-level dependency in JupyterLab extension pattern. | ai | |
| phantom-deps | phantom-dep:@emotion/styled | AI (phantom-deps): Config-level dependency in JupyterLab extension pattern. | ai | |
| phantom-deps | phantom-dep:nbdime-jupyterlab | AI (phantom-deps): Declared as singleton in jupyterlab sharedPackages config, not directly imported. | ai | |
| phantom-deps | phantom-dep:@jupyterlab/console | AI (phantom-deps): Same-org JupyterLab peer dependency; config-level reference is expected. | ai |
Versions (showing 14 of 14)
| Version | Deps | Published |
|---|---|---|
| 0.51.1 | 39 / 45 | |
| 0.51.0 | 39 / 45 | |
| 0.50.2 | 39 / 44 | |
| 0.50.1 | 39 / 44 | |
| 0.22.0 | 29 / 33 | |
| 0.20.0 | 22 / 30 | |
| 0.10.1 | 19 / 30 | |
| 0.10.0 | 19 / 28 | |
| 0.9.1 | 14 / 25 | |
| 0.9.0 | 14 / 25 | |
| 0.8.2 | 13 / 22 | |
| 0.8.1 | 13 / 22 | |
| 0.8.0 | 13 / 22 | |
| 0.7.0 | 12 / 22 |
v0.51.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.51.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.50.2
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (jupyterlab-release-bot) than the most recent previously approved version (fcollonval) on 2024-10-29, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.50.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.22.0
2 findingsThis version was published by a different npm account (fcollonval) than the most recent previously approved version (jaipreets) on 2020-10-04. It has since remained available on npm for 2119 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.20.0
2 findingsThis version was published by a different npm account (fcollonval) than the most recent previously approved version (jaipreets) on 2020-05-05. It has since remained available on npm for 2271 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.10.1
2 findingsThis version was published by a different npm account (fcollonval) than the most recent previously approved version (jaipreets) on 2020-04-25. It has since remained available on npm for 2281 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.10.0
2 findingsThis version was published by a different npm account (telamonian) than the most recent previously approved version (jaipreets) on 2020-03-26. It has since remained available on npm for 2311 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (blink1073) than the most recent previously approved version (jaipreets) on 2020-03-24, but blink1073 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.9.0
2 findingsThis version was published by a different npm account (telamonian) than the most recent previously approved version (jaipreets) on 2019-12-04. It has since remained available on npm for 2424 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.7.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.