← Home

@lokalise/api-contracts

24
Versions
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures No source commit

Maintainers

bodrovisbotlokalisekibertoadcarlos_gameroaplokalisefilippos.mikropoulosandrew_lokalisedariacmroger.gros-lokalisecasamitjanabartoszdrozd-lokalisejhfedzntrpilot-lokalise

Keywords

apicontractscontractfrontendbackendsinglesourcetruth

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): SLSA provenance attestation present; stronger integrity signal than gitHead. Org package with consistent CI publishing. ai
provenance publisher-changed AI (provenance): Transition from botlokalise to GitHub Actions CI/CD is a legitimate infra change, confirmed by SLSA provenance attestation. ai
maintainer-change maintainer-removed AI (maintainer-change): Removal of individual maintainer consistent with org moving to automated CI publishing; SLSA attestation confirms legitimate org control. ai
publish-pattern dormant-publish AI (publish-pattern): Dormancy followed by CI/CD migration is a plausible explanation; SLSA provenance attestation mitigates takeover risk. ai

Versions (showing 24 of 24)

Version Deps Published
7.1.0 0 / 9
7.0.0 0 / 9
6.15.0 0 / 9
6.14.0 0 / 9
6.13.1 0 / 9
6.13.0 0 / 9
6.12.0 0 / 9
6.11.0 0 / 9
6.10.0 0 / 8
6.9.0 0 / 8
6.8.0 0 / 8
6.7.0 0 / 8
6.6.0 0 / 8
6.5.3 0 / 8
6.5.2 0 / 8
6.5.1 0 / 8
6.5.0 0 / 8
6.4.0 0 / 8
6.3.0 0 / 8
6.2.1 0 / 8
6.2.0 0 / 8
6.1.1 0 / 8
6.1.0 0 / 8
6.0.0 0 / 8

v7.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.15.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.