← Home

@libp2p/echo

Implementation of an Echo protocol

26
Versions
Apache-2.0 OR MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

daviddiasalanshawachingbrainvascosantosnpm-service-account-libp2pjacobheun

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition from human publisher to GitHub Actions CI/CD is confirmed by SLSA provenance attestation; expected for libp2p monorepo. ai
publish-pattern dormant-publish AI (publish-pattern): Dormancy followed by CI/CD migration is consistent with monorepo tooling changes, not account takeover. ai

Versions (showing 26 of 26)

Version Deps Published
3.1.10 5 / 6
3.1.9 5 / 6
3.1.8 5 / 6
3.1.7 5 / 6
3.1.6 5 / 6
3.1.5 5 / 5
3.1.4 5 / 5
3.1.3 5 / 5
3.1.2 5 / 5
3.1.0 5 / 5
3.0.15 6 / 4
3.0.14 6 / 4
3.0.13 6 / 4
3.0.12 6 / 4
3.0.11 6 / 4
3.0.10 6 / 4
3.0.9 6 / 4
3.0.8 6 / 4
3.0.7 6 / 4
3.0.6 6 / 4
3.0.5 6 / 4
3.0.4 6 / 4
3.0.3 6 / 4
3.0.2 6 / 4
3.0.1 6 / 4
3.0.0 6 / 4

v3.1.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.