← Home

@libp2p/keychain

20
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

daviddiasalanshawachingbrainvascosantosnpm-service-account-libp2pjacobheun

Keywords

IPFScryptoencryptionkeyslibp2psecure

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition from human publisher (achingbrain) to GitHub Actions is the expected pattern for CI/CD adoption; SLSA attestation confirms release originates from the official libp2p/js-libp2p repo. ai
publish-pattern dormant-publish AI (publish-pattern): Package is part of the libp2p/js-libp2p monorepo; per-package dormancy is normal in monorepos. SLSA attestation confirms legitimate provenance. ai

Versions (showing 20 of 20)

Version Deps Published
6.1.5 8 / 3
6.1.4 8 / 3
6.1.3 8 / 3
6.1.2 8 / 3
6.1.1 8 / 3
6.1.0 8 / 3
6.0.14 8 / 3
6.0.12 8 / 3
6.0.11 8 / 3
6.0.10 8 / 3
6.0.9 8 / 3
6.0.8 8 / 3
6.0.7 8 / 3
6.0.6 8 / 3
6.0.5 8 / 3
6.0.4 8 / 3
6.0.3 8 / 3
6.0.2 8 / 3
6.0.1 8 / 3
6.0.0 8 / 3

v6.1.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.1.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.