← Home

@makeswift/runtime

4
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

alexhwoodsjoshuawootonnfikrimakeswiftmiguelolleragurtovoy-msferrataarvinpoddar

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@makeswift/controls AI (dependencies): First-party @makeswift scoped package; stable dependency pattern for this package. ai
dependencies unvetted-dep:@makeswift/next-plugin AI (dependencies): First-party @makeswift scoped package; stable dependency pattern for this package. ai
dependencies unvetted-dep:@makeswift/prop-controllers AI (dependencies): First-party @makeswift scoped package; stable dependency pattern for this package. ai
dependencies unvetted-dep:corporate-ipsum AI (dependencies): Benign lorem-ipsum utility; no security risk for this package. ai
phantom-deps phantom-dep:cors AI (phantom-deps): Phantom-dep heuristic false positive; stable for this package. ai
phantom-deps phantom-dep:@emotion/sheet AI (phantom-deps): Phantom-dep heuristic false positive; stable for this package. ai

Versions (showing 4 of 4)

Version Deps Published
0.28.6 41 / 42
0.28.5 41 / 42
0.28.4 41 / 41
0.28.3 41 / 41

v0.28.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.28.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.28.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.28.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.