@ledgerhq/types-live
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | no-provenance | AI (provenance): LedgerHQ publishes via CI automation; lack of Sigstore provenance is consistent across their package family and not a meaningful risk signal here. | ai |
Versions (showing 51 of 115)
| Version | Deps | Published |
|---|---|---|
| 6.115.0 | 2 / 11 | |
| 6.114.0 | 3 / 11 | |
| 6.113.0 | 3 / 11 | |
| 6.112.0 | 3 / 11 | |
| 6.111.0 | 3 / 11 | |
| 6.110.0 | 3 / 11 | |
| 6.109.0 | 3 / 11 | |
| 6.108.0 | 3 / 11 | |
| 6.107.0 | 3 / 11 | |
| 6.106.0 | 3 / 11 | |
| 6.105.0 | 3 / 11 | |
| 6.104.0 | 3 / 11 | |
| 6.103.0 | 3 / 11 | |
| 6.102.0 | 3 / 11 | |
| 6.101.0 | 3 / 11 | |
| 6.100.0 | 3 / 11 | |
| 6.99.0 | 3 / 11 | |
| 6.98.0 | 3 / 11 | |
| 6.97.0 | 3 / 11 | |
| 6.96.0 | 3 / 11 | |
| 6.95.0 | 3 / 11 | |
| 6.94.0 | 3 / 11 | |
| 6.93.0 | 3 / 11 | |
| 6.92.0 | 3 / 10 | |
| 6.91.1 | 3 / 10 | |
| 6.91.0 | 3 / 10 | |
| 6.90.0 | 2 / 10 | |
| 6.89.0 | 2 / 10 | |
| 6.88.0 | 2 / 10 | |
| 6.87.0 | 2 / 10 | |
| 6.86.0 | 2 / 10 | |
| 6.85.0 | 2 / 10 | |
| 6.84.0 | 2 / 10 | |
| 6.83.0 | 2 / 10 | |
| 6.82.0 | 2 / 10 | |
| 6.81.0 | 2 / 10 | |
| 6.80.0 | 2 / 10 | |
| 6.79.0 | 2 / 10 | |
| 6.78.0 | 2 / 10 | |
| 6.77.0 | 2 / 10 | |
| 6.76.0 | 2 / 10 | |
| 6.75.0 | 2 / 10 | |
| 6.74.0 | 2 / 10 | |
| 6.73.0 | 2 / 10 | |
| 6.72.0 | 2 / 10 | |
| 6.71.0 | 2 / 10 | |
| 6.70.0 | 2 / 10 | |
| 6.69.0 | 2 / 10 | |
| 6.68.0 | 2 / 10 | |
| 6.67.0 | 2 / 10 | |
| 6.66.0 | 2 / 10 |
v6.115.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.114.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.113.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.68.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.67.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.66.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.