@learncard/learn-cloud-plugin
[<img src="https://user-images.githubusercontent.com/2185016/190510561-294db809-09fd-4771-9749-6c0e0f4144fd.png" width="215"/>](https://learncard.com)
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:lodash | AI (phantom-deps): lodash is a declared runtime dep; phantom-dep fires due to bundled output, not a real missing import. | ai | |
| phantom-deps | phantom-dep:pbkdf2-hmac | AI (phantom-deps): pbkdf2-hmac is a declared runtime dep; phantom-dep fires due to bundled output pattern. | ai | |
| phantom-deps | phantom-dep:json-stringify-deterministic | AI (phantom-deps): json-stringify-deterministic is a declared runtime dep; phantom-dep fires due to bundled output pattern. | ai |
Versions (showing 19 of 19)
| Version | Deps | Published |
|---|---|---|
| 2.3.25 | 7 / 12 | |
| 2.3.24 | 7 / 12 | |
| 2.3.23 | 7 / 12 | |
| 2.3.22 | 7 / 12 | |
| 2.3.21 | 7 / 12 | |
| 2.3.20 | 7 / 12 | |
| 2.3.16 | 7 / 12 | |
| 2.3.13 | 7 / 12 | |
| 2.3.12 | 7 / 12 | |
| 2.3.11 | 7 / 12 | |
| 2.3.10 | 7 / 12 | |
| 2.3.9 | 7 / 12 | |
| 2.3.6 | 7 / 12 | |
| 2.3.4 | 7 / 12 | |
| 2.3.3 | 7 / 12 | |
| 2.3.2 | 7 / 12 | |
| 2.2.10 | 7 / 12 | |
| 2.2.9 | 7 / 12 | |
| 2.2.8 | 7 / 12 |
v2.3.13
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.3.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.3.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.3.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.3.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.3.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.3.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.3.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.3.2
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (taylorbeeston) on 2025-12-19, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v2.2.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.