← Home

@libp2p/daemon

libp2p-daemon JavaScript implementation

16
Versions
Apache-2.0 OR MIT
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures gitHead linked

Maintainers

daviddiasalanshawachingbrainvascosantosnpm-service-account-libp2pjacobheun

Keywords

libp2p

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): achingbrain is the established js-libp2p maintainer; transition from CI service account back to maintainer account is expected and benign. ai
dependencies unvetted-dep:es-main AI (dependencies): es-main is a small, benign ESM entry-point helper; stable false positive for this package. ai
dependencies unvetted-dep:yargs-promise AI (dependencies): yargs-promise is a well-known yargs wrapper; no malicious indicators, stable false positive. ai

Versions (showing 16 of 16)

Version Deps Published
6.0.33 5 / 3
6.0.32 5 / 3
6.0.31 5 / 3
6.0.30 5 / 3
6.0.29 5 / 3
6.0.28 5 / 3
6.0.27 5 / 3
6.0.26 5 / 3
6.0.21 5 / 3
6.0.19 5 / 3
6.0.16 5 / 3
6.0.15 5 / 3
6.0.14 5 / 3
6.0.13 5 / 3
6.0.11 5 / 3
6.0.10 5 / 3

v6.0.33

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.0.32

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.0.31

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.