← Home

@lerna-lite/version

23
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

ghiscoding

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:handlebars AI (dependencies): Widely-used templating lib, needed for changelog generation. ai
publish-pattern new-deps-added AI (publish-pattern): Deps are legitimate additions matching package's changelog/templating purpose. ai
phantom-deps phantom-dep:@conventional-changelog/template AI (phantom-deps): Used via config-driven templating, not direct import; expected pattern. ai
phantom-deps phantom-dep:@lerna-lite/cli AI (phantom-deps): Same-org sibling package; declared as peer/optional dep, not directly imported by this sub-package. ai
phantom-deps phantom-dep:conventional-changelog-angular AI (phantom-deps): Referenced in config files as a changelog preset, not a direct import — stable false positive for this package. ai
phantom-deps phantom-dep:@octokit/plugin-enterprise-rest AI (phantom-deps): Referenced in config/type files, not directly imported — stable false positive for this package. ai

Versions (showing 23 of 23)

Version Deps Published
5.4.2 18 / 0
5.4.1 18 / 0
5.4.0 18 / 0
5.3.0 16 / 0
5.2.2 21 / 0
5.2.1 21 / 0
5.2.0 22 / 0
5.1.0 22 / 0
5.0.0 22 / 0
4.11.5 23 / 0
4.11.4 29 / 0
4.11.3 29 / 0
4.11.2 29 / 0
4.11.1 29 / 0
4.11.0 29 / 0
4.10.5 29 / 0
4.10.4 29 / 0
4.10.3 29 / 0
4.10.2 29 / 0
4.10.1 29 / 0
4.10.0 29 / 0
4.9.4 29 / 0
4.9.3 29 / 0

v5.4.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.4.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.4.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.