@lemoncloud/ssocio2-backend-api
ssocio-v2 service backend api
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | no-provenance | AI (provenance): Internal API package; no provenance is consistent across all 95 versions and poses no exploit risk. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Internal/ecosystem API package; sparse metadata is consistent with private org tooling published publicly. | ai |
Versions (showing 49 of 49)
| Version | Deps | Published |
|---|---|---|
| 0.26.707 | 4 / 0 | |
| 0.26.701 | 4 / 0 | |
| 0.26.630 | 4 / 0 | |
| 0.26.526 | 4 / 0 | |
| 0.26.516 | 4 / 0 | |
| 0.26.514 | 4 / 0 | |
| 0.26.511 | 4 / 0 | |
| 0.26.507 | 4 / 0 | |
| 0.26.428 | 4 / 0 | |
| 0.26.419 | 4 / 0 | |
| 0.26.414 | 4 / 0 | |
| 0.26.323 | 4 / 0 | |
| 0.26.312 | 4 / 0 | |
| 0.26.219 | 4 / 0 | |
| 0.26.128 | 4 / 0 | |
| 0.25.1112 | 4 / 0 | |
| 0.25.1111 | 4 / 0 | |
| 0.25.1110 | 4 / 0 | |
| 0.25.1024 | 4 / 0 | |
| 0.25.1023 | 4 / 0 | |
| 0.25.924 | 4 / 0 | |
| 0.25.916 | 4 / 0 | |
| 0.25.730 | 4 / 0 | |
| 0.25.729 | 4 / 0 | |
| 0.25.728 | 4 / 0 | |
| 0.25.616 | 4 / 0 | |
| 0.25.527 | 4 / 0 | |
| 0.25.526 | 4 / 0 | |
| 0.25.522 | 4 / 0 | |
| 0.25.518 | 4 / 0 | |
| 0.25.404 | 4 / 0 | |
| 0.25.403 | 4 / 0 | |
| 0.25.402 | 4 / 0 | |
| 0.25.326 | 4 / 0 | |
| 0.25.212 | 4 / 0 | |
| 0.25.119 | 4 / 0 | |
| 0.25.113 | 4 / 0 | |
| 0.24.1209 | 4 / 0 | |
| 0.24.1208 | 4 / 0 | |
| 0.24.1114 | 4 / 0 | |
| 0.24.1113 | 4 / 0 | |
| 0.24.1029 | 4 / 0 | |
| 0.24.909 | 4 / 0 | |
| 0.24.824 | 4 / 0 | |
| 0.24.806 | 4 / 0 | |
| 0.24.805 | 4 / 0 | |
| 0.24.804 | 4 / 0 | |
| 0.24.624 | 5 / 0 | |
| 0.24.107 | 4 / 0 |
v0.26.707
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.26.701
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.26.630
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.25.404
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.25.403
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.25.402
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.25.326
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.25.212
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.25.119
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.25.113
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.24.1209
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.24.1208
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.24.1114
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.24.1113
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.24.1029
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.24.909
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.24.824
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.24.806
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.24.805
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.24.804
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.24.624
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.24.107
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.