← Home

@libp2p/floodsub

libp2p-floodsub, also known as pubsub-flood or just dumbsub, this implementation of pubsub focused on delivering an API for Publish/Subscribe, but with no CastTree Forming (it just floods the network).

27
Versions
Apache-2.0 OR MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

daviddiasalanshawachingbrainvascosantosnpm-service-account-libp2pjacobheun

Keywords

IPFSfloodfloodinggossiplibp2ppubsub

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition from achingbrain to GitHub Actions CI publishing is consistent with libp2p org automation; SLSA attestation confirms integrity. ai
publish-pattern dormant-publish AI (publish-pattern): Dormancy reflects monorepo release cadence; SLSA provenance attestation confirms legitimate CI-driven publish. ai

Versions (showing 27 of 27)

Version Deps Published
11.0.27 13 / 9
11.0.26 13 / 9
11.0.25 13 / 9
11.0.24 13 / 9
11.0.23 13 / 9
11.0.22 13 / 9
11.0.21 13 / 9
11.0.20 13 / 9
11.0.19 13 / 9
11.0.18 13 / 9
11.0.16 13 / 9
11.0.15 13 / 9
11.0.14 13 / 9
11.0.13 13 / 9
11.0.12 13 / 9
11.0.11 13 / 9
11.0.10 13 / 9
11.0.9 13 / 9
11.0.8 13 / 9
11.0.7 13 / 9
11.0.6 13 / 9
11.0.5 13 / 9
11.0.4 13 / 9
11.0.3 13 / 9
11.0.2 13 / 9
11.0.1 16 / 10
11.0.0 16 / 10

v11.0.27

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v11.0.26

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v11.0.25

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.