@ledgerhq/types-live
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | no-provenance | AI (provenance): LedgerHQ publishes via CI automation; lack of Sigstore provenance is consistent across their package family and not a meaningful risk signal here. | ai |
Versions (showing 100 of 116)
| Version | Deps | Published |
|---|---|---|
| 6.116.0 | 2 / 11 | |
| 6.115.0 | 2 / 11 | |
| 6.114.0 | 3 / 11 | |
| 6.113.0 | 3 / 11 | |
| 6.112.0 | 3 / 11 | |
| 6.111.0 | 3 / 11 | |
| 6.110.0 | 3 / 11 | |
| 6.109.0 | 3 / 11 | |
| 6.108.0 | 3 / 11 | |
| 6.107.0 | 3 / 11 | |
| 6.106.0 | 3 / 11 | |
| 6.105.0 | 3 / 11 | |
| 6.104.0 | 3 / 11 | |
| 6.103.0 | 3 / 11 | |
| 6.102.0 | 3 / 11 | |
| 6.101.0 | 3 / 11 | |
| 6.100.0 | 3 / 11 | |
| 6.99.0 | 3 / 11 | |
| 6.98.0 | 3 / 11 | |
| 6.97.0 | 3 / 11 | |
| 6.96.0 | 3 / 11 | |
| 6.95.0 | 3 / 11 | |
| 6.94.0 | 3 / 11 | |
| 6.93.0 | 3 / 11 | |
| 6.92.0 | 3 / 10 | |
| 6.91.1 | 3 / 10 | |
| 6.91.0 | 3 / 10 | |
| 6.90.0 | 2 / 10 | |
| 6.89.0 | 2 / 10 | |
| 6.88.0 | 2 / 10 | |
| 6.87.0 | 2 / 10 | |
| 6.86.0 | 2 / 10 | |
| 6.85.0 | 2 / 10 | |
| 6.84.0 | 2 / 10 | |
| 6.83.0 | 2 / 10 | |
| 6.82.0 | 2 / 10 | |
| 6.81.0 | 2 / 10 | |
| 6.80.0 | 2 / 10 | |
| 6.79.0 | 2 / 10 | |
| 6.78.0 | 2 / 10 | |
| 6.77.0 | 2 / 10 | |
| 6.76.0 | 2 / 10 | |
| 6.75.0 | 2 / 10 | |
| 6.74.0 | 2 / 10 | |
| 6.73.0 | 2 / 10 | |
| 6.72.0 | 2 / 10 | |
| 6.71.0 | 2 / 10 | |
| 6.70.0 | 2 / 10 | |
| 6.69.0 | 2 / 10 | |
| 6.68.0 | 2 / 10 | |
| 6.67.0 | 2 / 10 | |
| 6.66.0 | 2 / 10 | |
| 6.65.0 | 2 / 10 | |
| 6.64.0 | 2 / 10 | |
| 6.63.0 | 2 / 10 | |
| 6.62.0 | 2 / 10 | |
| 6.61.0 | 2 / 10 | |
| 6.60.0 | 2 / 10 | |
| 6.59.0 | 2 / 10 | |
| 6.58.0 | 2 / 10 | |
| 6.57.0 | 2 / 10 | |
| 6.56.0 | 2 / 10 | |
| 6.55.0 | 2 / 10 | |
| 6.54.0 | 2 / 10 | |
| 6.53.1 | 2 / 10 | |
| 6.53.0 | 2 / 10 | |
| 6.52.4 | 2 / 10 | |
| 6.52.3 | 2 / 10 | |
| 6.52.2 | 2 / 10 | |
| 6.52.1 | 2 / 10 | |
| 6.52.0 | 2 / 10 | |
| 6.51.1 | 2 / 10 | |
| 6.51.0 | 2 / 10 | |
| 6.50.0 | 2 / 10 | |
| 6.49.0 | 2 / 10 | |
| 6.48.1 | 2 / 10 | |
| 6.48.0 | 2 / 10 | |
| 6.47.0 | 2 / 10 | |
| 6.46.0 | 2 / 10 | |
| 6.45.0 | 2 / 10 | |
| 6.44.1 | 2 / 10 | |
| 6.44.0 | 2 / 10 | |
| 6.43.1 | 2 / 10 | |
| 6.43.0 | 2 / 10 | |
| 6.42.0 | 2 / 10 | |
| 6.41.1 | 2 / 10 | |
| 6.41.0 | 2 / 10 | |
| 6.40.0 | 2 / 10 | |
| 6.39.0 | 2 / 10 | |
| 6.38.1 | 2 / 10 | |
| 6.38.0 | 2 / 10 | |
| 6.37.0 | 2 / 10 | |
| 6.36.0 | 2 / 10 | |
| 6.35.1 | 2 / 10 | |
| 6.35.0 | 2 / 10 | |
| 6.34.1 | 2 / 10 | |
| 6.34.0 | 2 / 10 | |
| 6.33.0 | 2 / 10 | |
| 6.32.1 | 2 / 11 | |
| 6.32.0 | 2 / 11 |
v6.116.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.115.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.114.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.113.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.68.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.67.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.66.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.65.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.64.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.63.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.62.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.61.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.60.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.59.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.58.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.57.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.56.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.55.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.54.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.53.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.53.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.52.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.52.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.52.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.52.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.52.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.51.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.51.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.50.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.49.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.48.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.48.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.47.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.46.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.45.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.44.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.44.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.43.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.43.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.42.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.41.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.41.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.40.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.39.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.38.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.38.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.37.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.36.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.35.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.35.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.34.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.34.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.33.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.32.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.32.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.