← Home

@juzi/wechaty-puppet-rabbit

49
Versions
ISC
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

juzi-adminbinsee

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@juzi/wechaty AI (phantom-deps): Same-org scoped dependency; internal package structure. ai
phantom-deps phantom-dep:@juzi/wechaty-puppet-rabbit AI (phantom-deps): Self-referential scoped dep; internal package structure. ai
bogus-package bogus-package AI (bogus-package): Internal scoped package; missing metadata is typical for org-internal libraries. ai
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI publishing with SLSA attestation; legitimate supply chain improvement for this package. ai
npm-metadata no-description AI (npm-metadata): Established scoped package in @juzi org; missing description is a style issue, not a risk signal. ai

Versions (showing 49 of 49)

Version Deps Published
1.0.48 5 / 4
1.0.47 5 / 4
1.0.46 5 / 4
1.0.45 5 / 4
1.0.44 5 / 4
1.0.43 5 / 4
1.0.42 5 / 4
1.0.41 5 / 4
1.0.40 5 / 4
1.0.39 5 / 4
1.0.38 5 / 4
1.0.37 5 / 4
1.0.36 5 / 4
1.0.35 5 / 4
1.0.34 5 / 4
1.0.33 5 / 4
1.0.32 5 / 4
1.0.31 5 / 4
1.0.30 6 / 4
1.0.29 6 / 4
1.0.28 6 / 4
1.0.27 7 / 4
1.0.26 7 / 4
1.0.25 7 / 4
1.0.24 7 / 4
1.0.23 7 / 4
1.0.22 7 / 4
1.0.21 7 / 4
1.0.20 7 / 4
1.0.19 7 / 4
1.0.18 7 / 4
1.0.17 7 / 4
1.0.16 7 / 4
1.0.15 7 / 4
1.0.14 7 / 4
1.0.13 7 / 4
1.0.12 7 / 4
1.0.11 7 / 4
1.0.10 7 / 4
1.0.9 7 / 4
1.0.8 7 / 4
1.0.7 7 / 4
1.0.6 7 / 4
1.0.5 7 / 4
1.0.4 7 / 4
1.0.3 5 / 4
1.0.2 5 / 4
1.0.1 5 / 4
1.0.0 5 / 4

v1.0.48

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.47

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.22

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.21

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.20

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.19

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.18

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.