← Home

@libp2p/utils

25
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

daviddiasalanshawachingbrainvascosantosnpm-service-account-libp2pjacobheun

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:it-pipe AI (dependencies): it-pipe is a core streaming utility in the libp2p/js ecosystem; stable, well-known dependency appropriate for this package. ai
dependencies unvetted-dep:is-loopback-addr AI (dependencies): is-loopback-addr is a small, well-scoped utility for loopback address detection; appropriate for a networking utility package. ai
dependencies unvetted-dep:it-length-prefixed AI (dependencies): it-length-prefixed is a core streaming utility in the libp2p/js ecosystem; stable, well-known dependency appropriate for this package. ai
dependencies unvetted-dep:@sindresorhus/fnv1a AI (dependencies): @sindresorhus/fnv1a is a hashing utility from the reputable @sindresorhus namespace; appropriate for use in a networking utility package. ai

Versions (showing 25 of 25)

Version Deps Published
7.3.1 25 / 10
7.3.0 25 / 10
7.2.4 24 / 10
7.2.3 24 / 10
7.2.2 25 / 9
7.2.1 25 / 9
7.2.0 25 / 9
7.1.0 24 / 9
7.0.17 24 / 9
7.0.15 23 / 9
7.0.14 23 / 9
7.0.13 23 / 9
7.0.12 23 / 9
7.0.11 23 / 9
7.0.10 23 / 9
7.0.9 23 / 9
7.0.8 23 / 9
7.0.7 23 / 9
7.0.6 23 / 9
7.0.5 23 / 9
7.0.4 23 / 9
7.0.3 23 / 9
7.0.2 23 / 9
7.0.1 23 / 9
7.0.0 23 / 9

v7.3.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.2.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.