@lvce-editor/shared-process
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Reflect.get used in a Proxy trap to wrap process.argv — standard JS pattern, not obfuscation. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Established editor package with 795 versions; missing description is a stable characteristic, not a malice indicator. | ai | |
| provenance | publisher-changed | AI (provenance): Transition from levivilet to GitHub Actions CI/CD is consistent with automating releases; SLSA attestation confirms integrity. | ai | |
| dependencies | unvetted-dep:@lvce-editor/json-rpc | AI (dependencies): First-party @lvce-editor scoped dep from the same monorepo; stable pattern across versions. | ai | |
| dependencies | unvetted-dep:@lvce-editor/jsonc-parser | AI (dependencies): First-party @lvce-editor scoped dep from the same monorepo; stable pattern across versions. | ai | |
| dependencies | unvetted-dep:@lvce-editor/rpc-registry | AI (dependencies): First-party @lvce-editor scoped dep from the same monorepo; stable pattern across versions. | ai | |
| dependencies | unvetted-dep:@lvce-editor/pretty-error | AI (dependencies): First-party @lvce-editor scoped dep from the same monorepo; stable pattern across versions. | ai | |
| dependencies | unvetted-dep:@lvce-editor/ipc | AI (dependencies): First-party @lvce-editor scoped dep from the same monorepo; stable pattern across versions. | ai | |
| dependencies | unvetted-dep:@lvce-editor/assert | AI (dependencies): First-party @lvce-editor scoped dep from the same monorepo; stable pattern across versions. | ai | |
| phantom-deps | phantom-dep:@lvce-editor/auth-process | AI (phantom-deps): Same-org dep declared in package.json; phantom-dep heuristic fires as false positive for this package. | ai |
Versions (showing 51 of 627)
| Version | Deps | Published |
|---|---|---|
| 0.94.9 | 13 / 0 | |
| 0.94.8 | 13 / 0 | |
| 0.94.7 | 13 / 0 | |
| 0.94.6 | 13 / 0 | |
| 0.94.5 | 13 / 0 | |
| 0.94.4 | 13 / 0 | |
| 0.94.3 | 13 / 0 | |
| 0.94.2 | 13 / 0 | |
| 0.94.1 | 13 / 0 | |
| 0.94.0 | 13 / 0 | |
| 0.93.25 | 13 / 0 | |
| 0.93.24 | 13 / 0 | |
| 0.93.23 | 13 / 0 | |
| 0.93.22 | 13 / 0 | |
| 0.93.21 | 13 / 0 | |
| 0.93.20 | 13 / 0 | |
| 0.93.19 | 13 / 0 | |
| 0.93.18 | 13 / 0 | |
| 0.93.17 | 13 / 0 | |
| 0.93.16 | 13 / 0 | |
| 0.93.15 | 13 / 0 | |
| 0.93.14 | 13 / 0 | |
| 0.93.13 | 13 / 0 | |
| 0.93.12 | 13 / 0 | |
| 0.93.11 | 13 / 0 | |
| 0.93.10 | 13 / 0 | |
| 0.93.9 | 13 / 0 | |
| 0.93.8 | 13 / 0 | |
| 0.93.7 | 13 / 0 | |
| 0.93.6 | 13 / 0 | |
| 0.93.5 | 13 / 0 | |
| 0.93.4 | 13 / 0 | |
| 0.93.3 | 13 / 0 | |
| 0.93.2 | 13 / 0 | |
| 0.93.1 | 13 / 0 | |
| 0.93.0 | 13 / 0 | |
| 0.92.0 | 13 / 0 | |
| 0.91.30 | 13 / 0 | |
| 0.91.29 | 13 / 0 | |
| 0.91.28 | 13 / 0 | |
| 0.91.27 | 13 / 0 | |
| 0.91.26 | 13 / 0 | |
| 0.91.25 | 13 / 0 | |
| 0.91.24 | 13 / 0 | |
| 0.91.23 | 13 / 0 | |
| 0.91.22 | 13 / 0 | |
| 0.91.21 | 13 / 0 | |
| 0.91.20 | 13 / 0 | |
| 0.91.19 | 13 / 0 | |
| 0.91.18 | 13 / 0 | |
| 0.91.17 | 13 / 0 |
v0.94.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.94.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.94.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.94.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.94.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.94.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.94.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.94.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.94.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.94.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.93.25
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.93.24
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.93.23
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.93.22
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.93.21
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.93.20
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.93.19
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.93.18
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.93.17
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.93.16
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.93.15
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.93.14
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.93.13
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.93.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.93.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.93.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.93.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.93.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.93.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.93.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.93.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.93.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.93.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.93.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.93.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.93.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.92.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.91.30
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.91.29
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.91.28
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.91.27
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.91.26
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.91.25
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.91.24
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.91.23
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.91.22
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.91.21
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.91.20
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.91.19
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.91.18
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.91.17
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.